From: | "Greg Sabino Mullane" <greg(at)turnstep(dot)com> |
---|---|
To: | pgsql-hackers(at)postgresql(dot)org |
Subject: | Re: Similar to csvlog but not really, json logs? |
Date: | 2014-08-27 16:02:47 |
Message-ID: | aa86fd9c3b92bad6f13275d4872eed53@biglumber.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160
Stephen Frost wrote:
> To try to clarify that a bit, as it comes across as rather opaque even
> on my re-reading, consider a case where you can't have the
> "credit_card_number" field ever exported to an audit or log file, but
> you're required to log all other changes to a table. Then consider that
> such a situation extends to individual INSERT or UPDATE commands- you
> need the command logged, but you can't have the contents of that column
> in the log file.
Perhaps you need a better example. Storing raw credit cards in the database
is a bad idea (and potential PCI violation); audit/log files are only one
of the many ways things can leak out. Encrypting sensitive columns is a
solution that solves your auditing problem, and works on all current versions
of Postgres. :)
> Our current capabilities around logging and auditing are dismal
No arguments there.
- --
Greg Sabino Mullane greg(at)turnstep(dot)com
End Point Corporation http://www.endpoint.com/
PGP Key: 0x14964AC8 201408271200
http://biglumber.com/x/web?pk=2529DF6AB8F79407E94445B4BC9B906714964AC8
-----BEGIN PGP SIGNATURE-----
iEYEAREDAAYFAlP+AKgACgkQvJuQZxSWSsjf7gCg00BwRbwRi/UPrHBs1RdfWX/I
TRsAn2CDrG/ycetKOQFbn/4rnSSYPz9j
=Ju0B
-----END PGP SIGNATURE-----
From | Date | Subject | |
---|---|---|---|
Next Message | Alvaro Herrera | 2014-08-27 16:18:46 | Re: SKIP LOCKED DATA (work in progress) |
Previous Message | David E. Wheeler | 2014-08-27 15:59:03 | Missing plpgsql.o Symbols on OS X |