云数据库 GAUSSDB-操作审计:audit_system_function_exec

时间:2025-07-25 09:27:14

audit_system_function_exec

参数说明:这个参数表示在执行白名单内的系统函数时是否记录审计日志。该参数可在PDB级别设置。

参数类型:整型

参数单位:

取值范围:0、1

  • 0:表示关闭对系统函数执行的审计功能。
  • 1:表示开启对系统函数执行的审计功能。

默认值:0。在PDB场景内,若未设置该参数,则继承来自全局的设置。

设置方式:该参数属于SIGHUP类型参数,请参见表1中对应设置方法进行设置。

设置建议:推荐使用默认值。

设置不当的风险与影响:此参数设置为1,当数据库频繁执行白名单内系统函数时会频繁记录审计日志,导致性能下降。

支持记录审计的系统函数白名单如下表所示:

set_working_grand_version_num_manually

set_config

pg_cancel_backend

pg_cancel_session

pg_reload_conf

pg_rotate_logfile

pg_terminate_session

pg_terminate_backend

pg_create_restore_point

pg_start_backup

pg_stop_backup

pg_switch_xlog

pg_cbm_rotate_file

pg_cbm_get_merged_file

pg_cbm_recycle_file

pg_enable_delay_ddl_recycle

pg_disable_delay_ddl_recycle

gs_roach_stop_backup

gs_roach_enable_delay_ddl_recycle

gs_roach_disable_delay_ddl_recycle

gs_roach_switch_xlog

pg_last_xlog_receive_location

pg_xlog_replay_pause

pg_xlog_replay_resume

gs_pitr_clean_history_global_barriers

gs_pitr_archive_slot_force_advance

pg_create_physical_replication_slot_extern

gs_set_obs_delete_location

gs_hadr_do_switchover

gs_set_obs_delete_location_with_slotname

gs_streaming_dr_in_switchover

gs_upload_obs_file

gs_download_obs_file

gs_set_obs_file_context

gs_get_hadr_key_cn

pg_advisory_lock

pg_advisory_lock_shared

pg_advisory_unlock

pg_advisory_unlock_shared

pg_advisory_unlock_all

pg_advisory_xact_lock

pg_advisory_xact_lock_shared

pg_try_advisory_lock

pg_try_advisory_lock_shared

pg_try_advisory_xact_lock

pg_try_advisory_xact_lock_shared

pg_create_logical_replication_slot

pg_drop_replication_slot

pg_logical_slot_peek_changes

pg_logical_slot_get_changes

pg_logical_slot_get_binary_changes

pg_replication_slot_advance

pg_replication_origin_create

pg_replication_origin_drop

pg_replication_origin_session_setup

pg_replication_origin_session_reset

pg_replication_origin_session_progress

pg_replication_origin_xact_setup

pg_replication_origin_xact_reset

pg_replication_origin_advance

local_space_shrink

gs_space_shrink

pg_free_remain_segment

gs_fault_inject

gs_repair_file

local_clear_bad_block_info

gs_repair_page

-

-

-

-

-

在系统函数执行这类审计事件的审计记录中,object_name字段的内容为系统函数名,不再带函数参数。

support.huaweicloud.com/centralized-devg-v8-gaussdb/gaussdb-40-0375.html