[{"data":1,"prerenderedAt":994},["ShallowReactive",2],{"navigation_docs":3,"-logging-audit-compliance":429,"-logging-audit-compliance-surround":989},[4,35,159,201,289,326,413],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Getting Started","\u002Fgetting-started","1.getting-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fgetting-started\u002Fintroduction","1.getting-started\u002F1.introduction","i-lucide-info",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick Start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-zap",{"title":25,"path":26,"stem":27,"icon":28},"Agent Skills","\u002Fgetting-started\u002Fagent-skills","1.getting-started\u002F4.agent-skills","i-lucide-sparkles",{"title":30,"path":31,"stem":32,"icon":33},"vs Other Loggers","\u002Fgetting-started\u002Fvs-other-loggers","1.getting-started\u002F5.vs-other-loggers","i-lucide-scale",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Logging","\u002Flogging","2.logging",[40,45,50,55,60,65,70,99,127],{"title":41,"path":42,"stem":43,"icon":44},"Overview","\u002Flogging\u002Foverview","2.logging\u002F0.overview","i-lucide-list",{"title":46,"path":47,"stem":48,"icon":49},"Simple Logging","\u002Flogging\u002Fsimple-logging","2.logging\u002F1.simple-logging","i-lucide-terminal",{"title":51,"path":52,"stem":53,"icon":54},"Wide Events","\u002Flogging\u002Fwide-events","2.logging\u002F2.wide-events","i-lucide-layers",{"title":56,"path":57,"stem":58,"icon":59},"Structured Errors","\u002Flogging\u002Fstructured-errors","2.logging\u002F3.structured-errors","i-lucide-shield-alert",{"title":61,"path":62,"stem":63,"icon":64},"Catalogs","\u002Flogging\u002Fcatalogs","2.logging\u002F4.catalogs","i-lucide-book-open",{"title":66,"path":67,"stem":68,"icon":69},"Client Logging","\u002Flogging\u002Fclient-logging","2.logging\u002F5.client-logging","i-lucide-monitor",{"title":71,"icon":72,"path":73,"stem":74,"children":75,"page":34},"AI SDK","i-simple-icons-vercel","\u002Flogging\u002Fai-sdk","2.logging\u002F6.ai-sdk",[76,79,84,89,94],{"title":41,"path":77,"stem":78,"icon":44},"\u002Flogging\u002Fai-sdk\u002Foverview","2.logging\u002F6.ai-sdk\u002F01.overview",{"title":80,"path":81,"stem":82,"icon":83},"Usage","\u002Flogging\u002Fai-sdk\u002Fusage","2.logging\u002F6.ai-sdk\u002F02.usage","i-lucide-code",{"title":85,"path":86,"stem":87,"icon":88},"Options","\u002Flogging\u002Fai-sdk\u002Foptions","2.logging\u002F6.ai-sdk\u002F03.options","i-lucide-sliders",{"title":90,"path":91,"stem":92,"icon":93},"Metadata","\u002Flogging\u002Fai-sdk\u002Fmetadata","2.logging\u002F6.ai-sdk\u002F04.metadata","i-lucide-database",{"title":95,"path":96,"stem":97,"icon":98},"Telemetry","\u002Flogging\u002Fai-sdk\u002Ftelemetry","2.logging\u002F6.ai-sdk\u002F05.telemetry","i-lucide-activity",{"title":100,"icon":101,"path":102,"stem":103,"children":104,"page":34},"Better Auth","i-simple-icons-betterauth","\u002Flogging\u002Fbetter-auth","2.logging\u002F7.better-auth",[105,108,113,118,122],{"title":41,"path":106,"stem":107,"icon":44},"\u002Flogging\u002Fbetter-auth\u002Foverview","2.logging\u002F7.better-auth\u002F01.overview",{"title":109,"path":110,"stem":111,"icon":112},"Identify User","\u002Flogging\u002Fbetter-auth\u002Fidentify-user","2.logging\u002F7.better-auth\u002F02.identify-user","i-lucide-user-check",{"title":114,"path":115,"stem":116,"icon":117},"Middleware","\u002Flogging\u002Fbetter-auth\u002Fmiddleware","2.logging\u002F7.better-auth\u002F03.middleware","i-lucide-shield",{"title":119,"path":120,"stem":121,"icon":69},"Client Sync","\u002Flogging\u002Fbetter-auth\u002Fclient-sync","2.logging\u002F7.better-auth\u002F04.client-sync",{"title":123,"path":124,"stem":125,"icon":126},"Performance","\u002Flogging\u002Fbetter-auth\u002Fperformance","2.logging\u002F7.better-auth\u002F05.performance","i-lucide-gauge",{"title":128,"icon":129,"path":130,"stem":131,"children":132,"page":34},"Audit Logs","i-lucide-shield-check","\u002Flogging\u002Faudit","2.logging\u002F8.audit",[133,136,141,146,151,155],{"title":41,"path":134,"stem":135,"icon":44},"\u002Flogging\u002Faudit\u002Foverview","2.logging\u002F8.audit\u002F01.overview",{"title":137,"path":138,"stem":139,"icon":140},"Schema","\u002Flogging\u002Faudit\u002Fschema","2.logging\u002F8.audit\u002F02.schema","i-lucide-file-text",{"title":142,"path":143,"stem":144,"icon":145},"Recording","\u002Flogging\u002Faudit\u002Frecording","2.logging\u002F8.audit\u002F03.recording","i-lucide-pen-line",{"title":147,"path":148,"stem":149,"icon":150},"Drains","\u002Flogging\u002Faudit\u002Fpipeline","2.logging\u002F8.audit\u002F04.pipeline","i-lucide-link",{"title":152,"path":153,"stem":154,"icon":129},"Compliance","\u002Flogging\u002Faudit\u002Fcompliance","2.logging\u002F8.audit\u002F05.compliance",{"title":156,"path":157,"stem":158,"icon":64},"Recipes","\u002Flogging\u002Faudit\u002Frecipes","2.logging\u002F8.audit\u002F06.recipes",{"title":160,"path":161,"stem":162,"children":163,"page":34},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[164,169,174,179,184,188,191,196],{"title":165,"path":166,"stem":167,"icon":168},"Lifecycle","\u002Fcore-concepts\u002Flifecycle","3.core-concepts\u002F0.lifecycle","i-lucide-arrow-right-left",{"title":170,"path":171,"stem":172,"icon":173},"Configuration","\u002Fcore-concepts\u002Fconfiguration","3.core-concepts\u002F1.configuration","i-lucide-settings",{"title":175,"path":176,"stem":177,"icon":178},"Sampling","\u002Fcore-concepts\u002Fsampling","3.core-concepts\u002F2.sampling","i-lucide-filter",{"title":180,"path":181,"stem":182,"icon":183},"Typed Fields","\u002Fcore-concepts\u002Ftyped-fields","3.core-concepts\u002F3.typed-fields","i-simple-icons-typescript",{"title":185,"path":186,"stem":187,"icon":129},"Best Practices","\u002Fcore-concepts\u002Fbest-practices","3.core-concepts\u002F4.best-practices",{"title":123,"path":189,"stem":190,"icon":126},"\u002Fcore-concepts\u002Fperformance","3.core-concepts\u002F5.performance",{"title":192,"path":193,"stem":194,"icon":195},"Vite Plugin","\u002Fcore-concepts\u002Fvite-plugin","3.core-concepts\u002F6.vite-plugin","i-custom-vite",{"title":197,"path":198,"stem":199,"icon":200},"Auto-Redaction","\u002Fcore-concepts\u002Fredaction","3.core-concepts\u002F7.redaction","i-lucide-eye-off",{"title":202,"path":203,"stem":204,"children":205,"page":34},"Frameworks","\u002Fframeworks","4.frameworks",[206,210,215,220,225,230,235,240,245,250,255,260,265,270,274,279,284],{"title":41,"path":207,"stem":208,"icon":209},"\u002Fframeworks\u002Foverview","4.frameworks\u002F00.overview","i-lucide-layout-grid",{"title":211,"path":212,"stem":213,"icon":214},"Nuxt","\u002Fframeworks\u002Fnuxt","4.frameworks\u002F01.nuxt","i-simple-icons-nuxtdotjs",{"title":216,"path":217,"stem":218,"icon":219},"Next.js","\u002Fframeworks\u002Fnextjs","4.frameworks\u002F02.nextjs","i-simple-icons-nextdotjs",{"title":221,"path":222,"stem":223,"icon":224},"SvelteKit","\u002Fframeworks\u002Fsveltekit","4.frameworks\u002F03.sveltekit","i-simple-icons-svelte",{"title":226,"path":227,"stem":228,"icon":229},"Nitro","\u002Fframeworks\u002Fnitro","4.frameworks\u002F04.nitro","i-custom-nitro",{"title":231,"path":232,"stem":233,"icon":234},"TanStack Start","\u002Fframeworks\u002Ftanstack-start","4.frameworks\u002F05.tanstack-start","i-custom-tanstack",{"title":236,"path":237,"stem":238,"icon":239},"NestJS","\u002Fframeworks\u002Fnestjs","4.frameworks\u002F06.nestjs","i-simple-icons-nestjs",{"title":241,"path":242,"stem":243,"icon":244},"Express","\u002Fframeworks\u002Fexpress","4.frameworks\u002F07.express","i-simple-icons-express",{"title":246,"path":247,"stem":248,"icon":249},"Hono","\u002Fframeworks\u002Fhono","4.frameworks\u002F08.hono","i-simple-icons-hono",{"title":251,"path":252,"stem":253,"icon":254},"Fastify","\u002Fframeworks\u002Ffastify","4.frameworks\u002F09.fastify","i-simple-icons-fastify",{"title":256,"path":257,"stem":258,"icon":259},"Elysia","\u002Fframeworks\u002Felysia","4.frameworks\u002F10.elysia","i-custom-elysia",{"title":261,"path":262,"stem":263,"icon":264},"React Router","\u002Fframeworks\u002Freact-router","4.frameworks\u002F11.react-router","i-custom-reactrouter",{"title":266,"path":267,"stem":268,"icon":269},"Cloudflare Workers","\u002Fframeworks\u002Fcloudflare-workers","4.frameworks\u002F12.cloudflare-workers","i-simple-icons-cloudflare",{"title":271,"path":272,"stem":273,"icon":183},"Standalone","\u002Fframeworks\u002Fstandalone","4.frameworks\u002F13.standalone",{"title":275,"path":276,"stem":277,"icon":278},"Astro","\u002Fframeworks\u002Fastro","4.frameworks\u002F14.astro","i-simple-icons-astro",{"title":280,"path":281,"stem":282,"icon":283},"AWS Lambda","\u002Fframeworks\u002Faws-lambda","4.frameworks\u002F16.aws-lambda","i-custom-lambda",{"title":285,"path":286,"stem":287,"icon":288},"Custom Integration","\u002Fframeworks\u002Fcustom-integration","4.frameworks\u002F17.custom-integration","i-lucide-puzzle",{"title":290,"path":291,"stem":292,"children":293,"page":34},"Build on top","\u002Fbuild-on-top","5.build-on-top",[294,297,302,307,312,317,321],{"title":41,"path":295,"stem":296,"icon":54},"\u002Fbuild-on-top\u002Foverview","5.build-on-top\u002F0.overview",{"title":298,"path":299,"stem":300,"icon":301},"Stream API","\u002Fbuild-on-top\u002Fstream-api","5.build-on-top\u002F1.stream-api","i-lucide-radio-tower",{"title":303,"path":304,"stem":305,"icon":306},"Stream server","\u002Fbuild-on-top\u002Fstream-server","5.build-on-top\u002F2.stream-server","i-lucide-radio",{"title":308,"path":309,"stem":310,"icon":311},"FS reader","\u002Fbuild-on-top\u002Ffs-reader","5.build-on-top\u002F3.fs-reader","i-lucide-folder-search",{"title":313,"path":314,"stem":315,"icon":316},"Identity headers","\u002Fbuild-on-top\u002Fidentity-headers","5.build-on-top\u002F4.identity-headers","i-lucide-fingerprint",{"title":156,"path":318,"stem":319,"icon":320},"\u002Fbuild-on-top\u002Frecipes","5.build-on-top\u002F5.recipes","i-lucide-chef-hat",{"title":322,"path":323,"stem":324,"icon":325},"Catalogs as packages","\u002Fbuild-on-top\u002Fcatalogs-as-packages","5.build-on-top\u002F6.catalogs-as-packages","i-lucide-package",{"title":327,"path":328,"stem":329,"children":330,"page":34},"Adapters","\u002Fadapters","6.adapters",[331,334,374,389],{"title":41,"path":332,"stem":333,"icon":44},"\u002Fadapters\u002Foverview","6.adapters\u002F01.overview",{"title":335,"path":336,"stem":337,"children":338,"page":34},"Cloud destinations","\u002Fadapters\u002Fcloud","6.adapters\u002F02.cloud",[339,344,349,354,359,364,369],{"title":340,"path":341,"stem":342,"icon":343},"Axiom","\u002Fadapters\u002Fcloud\u002Faxiom","6.adapters\u002F02.cloud\u002F01.axiom","i-custom-axiom",{"title":345,"path":346,"stem":347,"icon":348},"OTLP","\u002Fadapters\u002Fcloud\u002Fotlp","6.adapters\u002F02.cloud\u002F02.otlp","i-simple-icons-opentelemetry",{"title":350,"path":351,"stem":352,"icon":353},"PostHog","\u002Fadapters\u002Fcloud\u002Fposthog","6.adapters\u002F02.cloud\u002F03.posthog","i-simple-icons-posthog",{"title":355,"path":356,"stem":357,"icon":358},"Sentry","\u002Fadapters\u002Fcloud\u002Fsentry","6.adapters\u002F02.cloud\u002F04.sentry","i-simple-icons-sentry",{"title":360,"path":361,"stem":362,"icon":363},"Better Stack","\u002Fadapters\u002Fcloud\u002Fbetter-stack","6.adapters\u002F02.cloud\u002F05.better-stack","i-simple-icons-betterstack",{"title":365,"path":366,"stem":367,"icon":368},"Datadog","\u002Fadapters\u002Fcloud\u002Fdatadog","6.adapters\u002F02.cloud\u002F06.datadog","i-simple-icons-datadog",{"title":370,"path":371,"stem":372,"icon":373},"HyperDX","\u002Fadapters\u002Fcloud\u002Fhyperdx","6.adapters\u002F02.cloud\u002F07.hyperdx","i-custom-hyperdx",{"title":375,"path":376,"stem":377,"children":378,"page":34},"Self-hosted","\u002Fadapters\u002Fself-hosted","6.adapters\u002F03.self-hosted",[379,384],{"title":380,"path":381,"stem":382,"icon":383},"File System","\u002Fadapters\u002Fself-hosted\u002Ffs","6.adapters\u002F03.self-hosted\u002F01.fs","i-lucide-hard-drive",{"title":385,"path":386,"stem":387,"icon":388},"NuxtHub","\u002Fadapters\u002Fself-hosted\u002Fnuxthub","6.adapters\u002F03.self-hosted\u002F02.nuxthub","i-simple-icons-nuxt",{"title":390,"path":391,"stem":392,"children":393,"page":34},"Building blocks","\u002Fadapters\u002Fbuilding-blocks","6.adapters\u002F04.building-blocks",[394,399,404,408],{"title":395,"path":396,"stem":397,"icon":398},"Pipeline","\u002Fadapters\u002Fbuilding-blocks\u002Fpipeline","6.adapters\u002F04.building-blocks\u002F01.pipeline","i-lucide-workflow",{"title":400,"path":401,"stem":402,"icon":403},"HTTP","\u002Fadapters\u002Fbuilding-blocks\u002Fhttp","6.adapters\u002F04.building-blocks\u002F02.http","i-lucide-globe",{"title":405,"path":406,"stem":407,"icon":83},"Custom Adapters","\u002Fadapters\u002Fbuilding-blocks\u002Fcustom","6.adapters\u002F04.building-blocks\u002F03.custom",{"title":409,"path":410,"stem":411,"icon":412},"Toolkit","\u002Fadapters\u002Fbuilding-blocks\u002Ftoolkit","6.adapters\u002F04.building-blocks\u002F04.toolkit","i-lucide-blocks",{"title":414,"path":415,"stem":416,"children":417,"page":34},"Enrichers","\u002Fenrichers","7.enrichers",[418,421,425],{"title":41,"path":419,"stem":420,"icon":28},"\u002Fenrichers\u002Foverview","7.enrichers\u002F1.overview",{"title":422,"path":423,"stem":424,"icon":288},"Built-in","\u002Fenrichers\u002Fbuilt-in","7.enrichers\u002F2.built-in",{"title":426,"path":427,"stem":428,"icon":83},"Custom","\u002Fenrichers\u002Fcustom","7.enrichers\u002F3.custom",{"id":430,"title":152,"body":431,"description":978,"extension":979,"links":980,"meta":985,"navigation":986,"path":153,"seo":987,"stem":154,"__hash__":988},"docs\u002F2.logging\u002F8.audit\u002F05.compliance.md",{"type":432,"value":433,"toc":971},"minimark",[434,447,452,455,568,591,600,604,611,735,773,777,780,793,806,810,813,872,875,879,967],[435,436,437,438,442,443,446],"p",{},"Compliance frameworks (SOC2, HIPAA, GDPR, PCI) ask the same five questions of every audit log: ",[439,440,441],"strong",{},"who, what, when, from where, with which outcome",", plus ",[439,444,445],{},"how do we know it wasn't tampered with",". evlog answers each one through composition of the existing primitives.",[448,449,451],"h2",{"id":450},"integrity","Integrity",[435,453,454],{},"Hash-chain the audit log so any tampering is detectable. Each event's hash includes the previous hash, so deleting a row breaks the chain forward of that point.",[456,457,462],"pre",{"className":458,"code":459,"language":460,"meta":461,"style":461},"language-typescript shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","auditOnly(\n  signed(createFsDrain({ dir: '.audit' }), { strategy: 'hash-chain' }),\n  { await: true },\n)\n","typescript","",[463,464,465,478,544,562],"code",{"__ignoreMap":461},[466,467,470,474],"span",{"class":468,"line":469},"line",1,[466,471,473],{"class":472},"s2Zo4","auditOnly",[466,475,477],{"class":476},"sTEyZ","(\n",[466,479,481,484,487,490,492,496,500,503,506,510,513,516,519,522,525,528,530,532,535,537,539,541],{"class":468,"line":480},2,[466,482,483],{"class":472},"  signed",[466,485,486],{"class":476},"(",[466,488,489],{"class":472},"createFsDrain",[466,491,486],{"class":476},[466,493,495],{"class":494},"sMK4o","{",[466,497,499],{"class":498},"swJcz"," dir",[466,501,502],{"class":494},":",[466,504,505],{"class":494}," '",[466,507,509],{"class":508},"sfazB",".audit",[466,511,512],{"class":494},"'",[466,514,515],{"class":494}," }",[466,517,518],{"class":476},")",[466,520,521],{"class":494},",",[466,523,524],{"class":494}," {",[466,526,527],{"class":498}," strategy",[466,529,502],{"class":494},[466,531,505],{"class":494},[466,533,534],{"class":508},"hash-chain",[466,536,512],{"class":494},[466,538,515],{"class":494},[466,540,518],{"class":476},[466,542,543],{"class":494},",\n",[466,545,547,550,553,555,559],{"class":468,"line":546},3,[466,548,549],{"class":494},"  {",[466,551,552],{"class":498}," await",[466,554,502],{"class":494},[466,556,558],{"class":557},"sfNiH"," true",[466,560,561],{"class":494}," },\n",[466,563,565],{"class":468,"line":564},4,[466,566,567],{"class":476},")\n",[569,570,571,578,579,582,583,586,587,590],"warning",{},[439,572,573,574,577],{},"Rotate ",[463,575,576],{},"secret"," for HMAC-signed audits annually."," When you rotate, embed a key id alongside the signature (e.g. extend ",[463,580,581],{},"AuditFields"," with ",[463,584,585],{},"keyId"," via ",[463,588,589],{},"declare module",") so old events stay verifiable against the previous secret. Verifiers should look up the key by id, not assume a single global secret.",[435,592,593,594,599],{},"See ",[595,596,598],"a",{"href":597},"\u002Flogging\u002Faudit\u002Fpipeline#signed","Drains & Integrity"," for the difference between HMAC and hash-chain.",[448,601,603],{"id":602},"redact","Redact",[435,605,606,607,610],{},"Audit events run through your existing ",[463,608,609],{},"RedactConfig",". Compose with the strict audit preset to harden PII handling:",[456,612,614],{"className":458,"code":613,"language":460,"meta":461,"style":461},"import { auditRedactPreset } from 'evlog'\n\ninitLogger({\n  redact: {\n    paths: [\n      ...(auditRedactPreset.paths ?? []),\n      'user.password',\n    ],\n  },\n})\n",[463,615,616,640,646,656,666,677,700,713,721,727],{"__ignoreMap":461},[466,617,618,622,624,627,629,632,634,637],{"class":468,"line":469},[466,619,621],{"class":620},"s7zQu","import",[466,623,524],{"class":494},[466,625,626],{"class":476}," auditRedactPreset",[466,628,515],{"class":494},[466,630,631],{"class":620}," from",[466,633,505],{"class":494},[466,635,636],{"class":508},"evlog",[466,638,639],{"class":494},"'\n",[466,641,642],{"class":468,"line":480},[466,643,645],{"emptyLinePlaceholder":644},true,"\n",[466,647,648,651,653],{"class":468,"line":546},[466,649,650],{"class":472},"initLogger",[466,652,486],{"class":476},[466,654,655],{"class":494},"{\n",[466,657,658,661,663],{"class":468,"line":564},[466,659,660],{"class":498},"  redact",[466,662,502],{"class":494},[466,664,665],{"class":494}," {\n",[466,667,669,672,674],{"class":468,"line":668},5,[466,670,671],{"class":498},"    paths",[466,673,502],{"class":494},[466,675,676],{"class":476}," [\n",[466,678,680,683,686,689,692,695,698],{"class":468,"line":679},6,[466,681,682],{"class":494},"      ...",[466,684,685],{"class":476},"(auditRedactPreset",[466,687,688],{"class":494},".",[466,690,691],{"class":476},"paths ",[466,693,694],{"class":494},"??",[466,696,697],{"class":476}," [])",[466,699,543],{"class":494},[466,701,703,706,709,711],{"class":468,"line":702},7,[466,704,705],{"class":494},"      '",[466,707,708],{"class":508},"user.password",[466,710,512],{"class":494},[466,712,543],{"class":494},[466,714,716,719],{"class":468,"line":715},8,[466,717,718],{"class":476},"    ]",[466,720,543],{"class":494},[466,722,724],{"class":468,"line":723},9,[466,725,726],{"class":494},"  },\n",[466,728,730,733],{"class":468,"line":729},10,[466,731,732],{"class":494},"}",[466,734,567],{"class":476},[435,736,737,738,741,742,745,746,749,750,749,753,749,756,749,759,749,762,765,766,769,770,688],{},"The preset drops ",[463,739,740],{},"Authorization"," \u002F ",[463,743,744],{},"Cookie"," headers and common credential field names (",[463,747,748],{},"password",", ",[463,751,752],{},"token",[463,754,755],{},"apiKey",[463,757,758],{},"cardNumber",[463,760,761],{},"cvv",[463,763,764],{},"ssn",") wherever they appear inside ",[463,767,768],{},"audit.changes.before"," and ",[463,771,772],{},"audit.changes.after",[448,774,776],{"id":775},"gdpr-vs-append-only","GDPR vs append-only",[435,778,779],{},"Append-only audit logs collide with GDPR's right to be forgotten. Recommended pattern today:",[781,782,783,787,790],"ol",{},[784,785,786],"li",{},"Keep audit rows immutable.",[784,788,789],{},"Encrypt PII fields with a per-actor key (held outside the audit store).",[784,791,792],{},"To \"forget\" a user, delete their key — the audit row stays, the chain stays valid, the PII becomes unreadable.",[435,794,795,796,799,800,688],{},"A built-in ",[463,797,798],{},"cryptoShredding"," helper is on the ",[595,801,805],{"href":802,"rel":803},"https:\u002F\u002Fgithub.com\u002FHugoRCD\u002Fevlog\u002Fissues",[804],"nofollow","follow-up roadmap",[448,807,809],{"id":808},"retention","Retention",[435,811,812],{},"Retention is a storage-layer concern by design. evlog's audit layer doesn't enforce retention windows because every supported sink already has a stronger, audited mechanism for it. Pick the one matching your sink:",[814,815,816,829],"table",{},[817,818,819],"thead",{},[820,821,822,826],"tr",{},[823,824,825],"th",{},"Sink",[823,827,828],{},"Retention mechanism",[830,831,832,845,856,864],"tbody",{},[820,833,834,838],{},[835,836,837],"td",{},"FS",[835,839,840,841,844],{},"Combine ",[463,842,843],{},"createFsDrain({ maxFiles })"," with a daily compactor.",[820,846,847,850],{},[835,848,849],{},"Postgres",[835,851,852,853,688],{},"Schedule ",[463,854,855],{},"DELETE FROM audit_events WHERE timestamp \u003C now() - interval '7 years'",[820,857,858,861],{},[835,859,860],{},"Axiom \u002F Datadog \u002F Loki",[835,862,863],{},"Set the dataset retention policy in the platform.",[820,865,866,869],{},[835,867,868],{},"S3 Object Lock",[835,870,871],{},"Configure lifecycle rules + Object Lock retention period.",[435,873,874],{},"Document the chosen window in your security policy. Auditors care about the written rule, not the enforcing component.",[448,876,878],{"id":877},"common-pitfalls","Common Pitfalls",[880,881,882,895,918,924,943,957],"ul",{},[784,883,884,887,888,582,891,894],{},[439,885,886],{},"Logging only successes."," Auditors care most about denials. Always pair ",[463,889,890],{},"log.audit()",[463,892,893],{},"log.audit.deny()"," on the negative branch of every authorisation check.",[784,896,897,903,904,907,908,910,911,749,913,749,915,917],{},[439,898,899,900,688],{},"Leaking PII through ",[463,901,902],{},"changes"," ",[463,905,906],{},"auditDiff()"," runs through your ",[463,909,609],{},", but only if the field paths are listed. Add ",[463,912,748],{},[463,914,752],{},[463,916,755],{},", etc. once globally so you never have to think about it again.",[784,919,920,923],{},[439,921,922],{},"Treating audits as observability."," Don't sample, downsample, or summarise audit events. Force-keep is on by default — don't disable it.",[784,925,926,903,933,935,936,741,939,942],{},[439,927,928,929,932],{},"Conflating ",[463,930,931],{},"actor.id"," with the session id.",[463,934,931],{}," is the stable user id (or system identity). Correlate sessions via ",[463,937,938],{},"context.requestId",[463,940,941],{},"context.traceId",", never via the actor.",[784,944,945,948,949,952,953,956],{},[439,946,947],{},"Forgetting standalone jobs."," Cron tasks, queue workers, and CLIs trigger audit-worthy actions too. Use ",[463,950,951],{},"audit()"," (no request) or ",[463,954,955],{},"withAudit()"," to keep coverage parity with your HTTP routes.",[784,958,959,966],{},[439,960,961,962,965],{},"Skipping ",[463,963,964],{},"await: true"," on the audit drain."," Without it, audits are fire-and-forget — a crash between the event being emitted and the drain flushing means the action happened but no audit row exists.",[968,969,970],"style",{},"html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sfNiH, html code.shiki .sfNiH{--shiki-light:#FF5370;--shiki-default:#FF9CAC;--shiki-dark:#FF9CAC}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .s7zQu, html code.shiki .s7zQu{--shiki-light:#39ADB5;--shiki-light-font-style:italic;--shiki-default:#89DDFF;--shiki-default-font-style:italic;--shiki-dark:#89DDFF;--shiki-dark-font-style:italic}",{"title":461,"searchDepth":480,"depth":480,"links":972},[973,974,975,976,977],{"id":450,"depth":480,"text":451},{"id":602,"depth":480,"text":603},{"id":775,"depth":480,"text":776},{"id":808,"depth":480,"text":809},{"id":877,"depth":480,"text":878},"Integrity, redact presets, GDPR vs append-only, retention windows, and the most common pitfalls when shipping audit logs to production.","md",[981,984],{"label":598,"icon":150,"to":148,"color":982,"variant":983},"neutral","subtle",{"label":156,"icon":64,"to":157,"color":982,"variant":983},{},{"title":152,"icon":129},{"title":152,"description":978},"IyXFlsbKUUw38ViWHOK2P3nf1U68neZdA_NJqFNoilA",[990,992],{"title":147,"path":148,"stem":149,"description":991,"icon":150,"children":-1},"auditEnricher to auto-fill request context, auditOnly to route audits to a dedicated sink, and signed for tamper-evident HMAC or hash-chain integrity.",{"title":156,"path":157,"stem":158,"description":993,"icon":64,"children":-1},"File system, Axiom, and Postgres recipes for audit logs, plus mockAudit for tests and the full API reference.",1778336623929]