diff --git a/conf/defaults.ini b/conf/defaults.ini index 496bd88725f..5f63dbc2b45 100644 --- a/conf/defaults.ini +++ b/conf/defaults.ini @@ -47,6 +47,9 @@ root_url = %(protocol)s://%(domain)s:%(http_port)s/ # Log web requests router_logging = false +# This enables data proxy logging, default is false +data_proxy_logging = false + # the path relative working path static_root_path = public diff --git a/conf/sample.ini b/conf/sample.ini index 55238856ae8..0d2adb55a9f 100644 --- a/conf/sample.ini +++ b/conf/sample.ini @@ -49,6 +49,9 @@ # Log web requests ;router_logging = false +# This enables query request audit logging, output at warn level, default is false +;data_proxy_logging = false + # the path relative working path ;static_root_path = public diff --git a/docs/sources/http_api/admin.md b/docs/sources/http_api/admin.md index fc9b3177e52..8aa00d08618 100644 --- a/docs/sources/http_api/admin.md +++ b/docs/sources/http_api/admin.md @@ -143,6 +143,7 @@ with Grafana admin permission. "protocol":"http", "root_url":"%(protocol)s://%(domain)s:%(http_port)s/", "router_logging":"true", + "data_proxy_logging":"true", "static_root_path":"public" }, "session":{ diff --git a/pkg/api/dataproxy.go b/pkg/api/dataproxy.go index db4c5166feb..2c1355154bc 100644 --- a/pkg/api/dataproxy.go +++ b/pkg/api/dataproxy.go @@ -1,6 +1,8 @@ package api import ( + "bytes" + "io/ioutil" "net/http" "net/http/httputil" "net/url" @@ -8,6 +10,7 @@ import ( "github.com/grafana/grafana/pkg/api/cloudwatch" "github.com/grafana/grafana/pkg/bus" + "github.com/grafana/grafana/pkg/log" "github.com/grafana/grafana/pkg/metrics" "github.com/grafana/grafana/pkg/middleware" m "github.com/grafana/grafana/pkg/models" @@ -121,6 +124,24 @@ func ProxyDataSourceRequest(c *middleware.Context) { c.JsonApiErr(400, "Unable to load TLS certificate", err) return } + + proxyLog(ds.Type, c) + proxy.ServeHTTP(c.Resp, c.Req.Request) c.Resp.Header().Del("Set-Cookie") } + +func proxyLog(dataSourceType string, c *middleware.Context) { + if setting.DataProxyLogging { + auditLogger := log.New("data-proxy-log", "userid", c.UserId, "orgid", c.OrgId, "username", c.Login) + + var body string + if c.Req.Request.Body != nil { + buffer, _ := ioutil.ReadAll(c.Req.Request.Body) + c.Req.Request.Body = ioutil.NopCloser(bytes.NewBuffer(buffer)) + body = string(buffer) + } + + auditLogger.Info("Proxying incoming request", "datasource", dataSourceType, "uri", c.Req.RequestURI, "method", c.Req.Request.Method, "body", body) + } +} diff --git a/pkg/setting/setting.go b/pkg/setting/setting.go index 5189d28b445..6e3a2e2085f 100644 --- a/pkg/setting/setting.go +++ b/pkg/setting/setting.go @@ -66,6 +66,7 @@ var ( SshPort int CertFile, KeyFile string RouterLogging bool + DataProxyLogging bool StaticRootPath string EnableGzip bool EnforceDomain bool @@ -491,6 +492,7 @@ func NewConfigContext(args *CommandLineArgs) error { HttpAddr = server.Key("http_addr").MustString(DEFAULT_HTTP_ADDR) HttpPort = server.Key("http_port").MustString("3000") RouterLogging = server.Key("router_logging").MustBool(false) + DataProxyLogging = server.Key("data_proxy_logging").MustBool(false) EnableGzip = server.Key("enable_gzip").MustBool(false) EnforceDomain = server.Key("enforce_domain").MustBool(false) StaticRootPath = makeAbsolute(server.Key("static_root_path").String(), HomePath)