Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.

Trino Audit

The Trino Audit tab provisions the Superna Trino audit event-listener plugin. The plugin streams Trino query activity into the platform's audit store, so Trino activity appears alongside PowerScale, ObjectScale, and Kubernetes audit.

After the plugin is installed on a Trino server, every completed query produces audit records with:

  • The user who ran the query
  • The catalog, schema, and table that was read, written, or deleted
  • The full SQL text
  • Bytes, rows, and duration

Security Model​

The plugin does not connect to the database directly. It sends audit records to a single console endpoint, and the console stores them. The plugin authenticates with one ingest token, which grants access to that endpoint only. The token cannot reach any other API, setting, or data.

Status​

The status card at the top of the tab shows:

  • Token — whether an ingest token is configured.
  • Plugin JAR hosted — whether the plugin JAR is available on the console, and its version. If no JAR is hosted, contact Superna support to have it staged before you install on a Trino host.

Ingest Token​

Click Generate token, or Rotate token if one exists, to create the bearer token the plugin uses. The plaintext value is shown only once. Copy it and store it securely. It is stored encrypted and cannot be shown again.

Rotating invalidates the previous token immediately. Any plugin that still uses the old token stops ingesting until you reinstall it with the new one.

Console DNS​

Console DNS is an optional stable hostname for the console. It is included in the install command so Trino hosts reach the console by name and keep working if its IP address changes.

  • Enter a bare host, such as console.example.com, or host:port.
  • Do not include an http:// or https:// scheme.
  • Do not append the port you already use to browse the console. For a bare host, the console adds the current port itself, so host:<port> would become host:<port>:<port>.
  • Leave the field blank to use the address you are currently browsing from.

Install on a Trino Server​

Before you start, generate an ingest token and, if you use one, enter the Console DNS. Both are included in the install command.

If the console uses a self-signed certificate, which is the default on the appliance, read Console with a Self-Signed Certificate first.

  1. Copy the one-line install command.
  2. Run it on the Trino coordinator, as a user that can write to the Trino plugin/ and etc/ directories.
  3. Restart the Trino coordinator. Trino loads event listeners only at startup, so the plugin does not take effect until the restart.
  4. Run a query on Trino, then confirm that it appears in the audit data. See Structured Data Audit (Trino).

The install script does the following:

  • Downloads the plugin JAR from the console, authenticating with your token.
  • Places the JAR in plugin/superna-audit/.
  • Writes the event-listener configuration, including the console URL and your token.
  • Reminds you to restart the coordinator.

If the console refuses the request, for example because the token has a stray character pasted into it, the command prints ERROR: with the reason, exits with an error, and installs nothing. Do not restart the coordinator. Fix what the message names and run the command again.

Console with a Self-Signed Certificate​

If the console uses a self-signed certificate, which is the default on the appliance, the standard install command fails when it downloads the JAR. Use one of these options:

  • Install the console's CA certificate on the Trino host.
  • Add &tlsSkipVerify=true to the install.sh URL and fetch the installer with curl -k. The script then downloads the JAR with curl -k and sets superna-audit.tls-skip-verify=true so that plugin ingest also works over the self-signed connection.

Troubleshooting​

SymptomWhat to check
Trino queries do not appear in auditConfirm that the coordinator was restarted after installation. Confirm that the token in etc/event-listener.d/superna-audit.properties matches the current token. Rotating a token invalidates the old one. Confirm that the Trino host can reach the console URL.
The install command prints ERROR: invalid token formatThe token is not valid. A token contains only letters, digits, -, and _, and is often pasted with a stray character. Nothing was installed. Paste the token you saved and run the command again. If it is lost, generate or rotate one on this tab. Rotating replaces the token on every coordinator already installed.
Ingest returns 401The token is wrong or was rotated. Rotate the token on this tab and reinstall the plugin.
Install fails at Downloading plugin JAR, or with TLS or certificate errorsThe console uses a self-signed certificate. See Console with a Self-Signed Certificate.