I've made a little progress on what I optimistically think will be an 
acceptable solution. If any know of a better way, I am teachable.  I get 
user and service information as related to any delegate request by routing 
the following to a separate appender.

org.pac4j.saml.credentials.SAML2Credentials -- INFO
org.apereo.cas.web.flow.DelegatedClientAuthenticationAction  -- DEBUG

----  I do have an addtional related question:

Is it possible that client/x-ff IP is routed to MDC or some mechanism such 
that I could append it to the log format for this particular 
appender/logifie?

Thanks,

Andrew Marker

On Tuesday, October 22, 2019 at 1:06:15 PM UTC-5, Andrew Marker wrote:
>
> Hi all,
>
> I currently have what I assume is a relatively vanilla logging config with 
> some minor tweaks to prevent filling the drive on the servers.  We are 
> beginning in earnest work to leverage Delegate Auth with CAS 5.3.12.1 and 
> one of the items I'd like to do if possible would have one or the other of 
> these two outcomes.
>
> In addition to the current logging:
>
> 1. Add a log appender for all delegate auth events.
>
> 2. Target just a specific delegate auth provider, and log just those 
> events to an appender.
>
> I'm working with a specific IDP that would like to see the traffic happens 
> for their users in our system. We have an existing trust relationship where 
> I could share the audit log without concern, but there is a lot of 
> irrelevant to in that.
>
> Thanks in advance for the suggestions.
>
> Andrew Marker
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/9d57aa4f-5dd6-47c6-bc6e-2259d4f7b7c1%40apereo.org.

Reply via email to