[SERVER-50991] audit createIndex on empty collection Created: 17/Sep/20  Updated: 29/Oct/23  Resolved: 18/Feb/21

Status: Closed
Project: Core Server
Component/s: Index Maintenance
Affects Version/s: None
Fix Version/s: 4.9.0

Type: Improvement Priority: Major - P3
Reporter: Sara Golemon Assignee: Shreyas Kalyan
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Related
is related to SERVER-50394 mongod audit log attributes DDL opera... Closed
Backwards Compatibility: Fully Compatible
Sprint: Security 2021-02-22
Participants:
Case:

 Comments   
Comment by Githook User [ 18/Feb/21 ]

Author:

{'name': 'Shreyas Kalyan', 'email': 'shreyas.kalyan@10gen.com', 'username': 'shreyaskalyan'}

Message: SERVER-50991 audit createIndex on empty collection
Branch: master
https://github.com/mongodb/mongo/commit/d4ba949ae491636a4e29c2b76671d7127bada407

Comment by Githook User [ 18/Feb/21 ]

Author:

{'name': 'Shreyas Kalyan', 'email': 'shreyas.kalyan@10gen.com', 'username': 'shreyaskalyan'}

Message: SERVER-50991 audit createIndex on empty collection
Branch: master
https://github.com/10gen/mongo-enterprise-modules/commit/e5a9ffd5b061a670540ba8ce23fd0e17c2e51e31

Comment by Eric Milkie [ 12/Feb/21 ]

I wouldn't spend extra effort to change the natural behavior, which sounds like it will be "audit the _id index when it is automatically created with a new collection". I think I prefer that behavior as well.

Comment by Shreyas Kalyan [ 11/Feb/21 ]

milkie This is a good question. I think it is a non-trivial amount of work to not audit the _id index that is created. I think it is not a bad thing to audit the _id field as well; the only potential downside I could think of is extra spam on the audit log. Is this a strong enough reason / is there a stronger reason to not include the _id field? Or were you advocating for the _id field to be audited?

Comment by Eric Milkie [ 03/Feb/21 ]

Will this include auditing the _id index that is automatically created when a collection is created?

Generated at Thu Feb 08 05:24:12 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.