When using the JSON Logging Layout for the Audit Logs and Delegated SAML Auth the verbosity is extreme to the point that a single login event is roughly 27KiB of log output. Is there a config setting I can use to quiet this down without throwing away the entire "what" field? As it stands right now it is logging everything we get back from the primary SAML2 instance at least 6 times per each TICKET_GRANTING_TICKET_CREATED and each AUTHENTICATION_SUCCESS Audit log event. (Yes, we write these out, it is how they get imported to our SEIM.)
-- ---------------------------+--------------------------------
Drew Northup |
University of Maine System | drew.n...@Maine.edu
Computing Center |
Orono, ME 04469 |