Server Audit Settings
Server Audit Settings controls how long structured audit events are retained and the storage budget used for coverage reporting.
Where to find it: Cluster Settings > Server Audit, or the root Server Audit Settings page.
Available to: root.
What this page does
The page compares configured and effective retention, event volume, estimated storage, and coverage. Pruning is time-based; the storage budget supports capacity reporting and planning rather than silently deleting individual events by size.
Before you start
Know legal/support retention requirements and current disk capacity. Export incident evidence before pruning. In a cluster, treat this as shared audit policy.
Policy limits
- Retention: minimum 30 days, maximum 3,650 days.
- Storage budget: whole number from 1 to 1,024 GB; the standard recommendation is at least 5 GB.
- Save: updates retention first, then stores the reporting budget.
- Prune now: permanently removes events older than the current retention window.
- Utilization: estimates coverage from event volume at roughly 600 bytes per event; actual storage can differ.
Controls and fields
| Control, Field, Or Section | What It Does | What It Affects | Recommended Usage |
|---|---|---|---|
| Audit history coverage | Shows how many days of audit data are currently represented and the configured coverage limit. | Gives context for how far back investigations can go. | Use before promising customers that older evidence exists. |
| Events stored since / Most recent event | Shows oldest and latest audit event timestamps. | Confirms whether the audit trail covers the incident window. | If the incident predates oldest event, export/request other evidence. |
| Storage usage | Shows estimated audit size against the configured audit budget. | Capacity planning signal; pruning remains retention-based. | Increase budget if utilization stays high and audit history is important. |
| Audit Retention Minimum | Minimum days audit events should be retained. | Controls retention policy used for audit pruning. | Use 30+ days in production; longer if compliance requires it. |
| Audit Storage Allocation | Cluster-wide storage budget used for utilization reporting. | Does not directly prune events; helps operators understand storage pressure. | Set a realistic budget rather than treating it as an exact hard limit. |
| Last prune run | Shows the last audit prune execution time. | Indicates whether cleanup has been run before. | Review before manually pruning. |
| Save Policy | Saves retention and storage budget and requests settings sync. | Changes future audit retention behavior. | Save only after confirming compliance/support retention requirements. |
| Prune Now | Deletes audit events older than the policy after hostname confirmation. | Permanently removes old audit evidence. | Export required data first and avoid pruning during active investigations. |
Safety notes
- Pruning removes historical audit data. Export data first if it is needed for compliance or support.
How to use it
- Read configured, effective, and estimated coverage.
- Choose a retention that meets policy and a realistic storage budget.
- Save and confirm the returned state.
- Use Prune now only after confirming the window and preserving required evidence.
- Recheck Audit search at the oldest expected date.
Result and next check
Audit reports at least the configured retention and an understood capacity budget. Pruned history cannot be recovered from the live audit table; use backups/exports where policy requires longer preservation.
Theme color