Trino Audit
The Trino Audit tab provisions the Superna Trino audit event-listener plugin. The plugin streams Trino query activity into the platform's audit store, so Trino activity appears alongside PowerScale, ObjectScale, and Kubernetes audit.
After the plugin is installed on a Trino server, every completed query produces audit records with:
- The user who ran the query
- The catalog, schema, and table that was read, written, or deleted
- The full SQL text
- Bytes, rows, and duration
Security Model
The plugin does not connect to the database directly. It sends audit records to a single console endpoint, and the console stores them. The plugin authenticates with one ingest token, which grants access to that endpoint only. The token cannot reach any other API, setting, or data.
Status
The status card at the top of the tab shows:
- Token — whether an ingest token is
configured. - Plugin JAR hosted — whether the plugin JAR is available on the console, and its version. If no JAR is hosted, contact Superna support to have it staged before you install on a Trino host.
Ingest Token
Click Generate token, or Rotate token if one exists, to create the bearer token the plugin uses. The plaintext value is shown only once. Copy it and store it securely. It is stored encrypted and cannot be shown again.
Rotating invalidates the previous token immediately. Any plugin that still uses the old token stops ingesting until you reinstall it with the new one.
Console DNS
Console DNS is an optional stable hostname for the console. It is included in the install command so Trino hosts reach the console by name and keep working if its IP address changes.
- Enter a bare host, such as
console.example.com, orhost:port. - Do not include an
http://orhttps://scheme. - Do not append the port you already use to browse the console. For a bare host, the console adds the current port itself, so
host:<port>would becomehost:<port>:<port>. - Leave the field blank to use the address you are currently browsing from.
Install on a Trino Server
Before you start, generate an ingest token and, if you use one, enter the Console DNS. Both are included in the install command.
If the console uses a self-signed certificate, which is the default on the appliance, read Console with a Self-Signed Certificate first.
- Copy the one-line install command.
- Run it on the Trino coordinator, as a user that can write to the Trino
plugin/andetc/directories. - Restart the Trino coordinator. Trino loads event listeners only at startup, so the plugin does not take effect until the restart.
- Run a query on Trino, then confirm that it appears in the audit data. See Structured Data Audit (Trino).
The install script does the following:
- Downloads the plugin JAR from the console, authenticating with your token.
- Places the JAR in
plugin/superna-audit/. - Writes the event-listener configuration, including the console URL and your token.
- Reminds you to restart the coordinator.
If the console refuses the request, for example because the token has a stray character pasted into it, the command prints ERROR: with the reason, exits with an error, and installs nothing. Do not restart the coordinator. Fix what the message names and run the command again.
Console with a Self-Signed Certificate
If the console uses a self-signed certificate, which is the default on the appliance, the standard install command fails when it downloads the JAR. Use one of these options:
- Install the console's CA certificate on the Trino host.
- Add
&tlsSkipVerify=trueto theinstall.shURL and fetch the installer withcurl -k. The script then downloads the JAR withcurl -kand setssuperna-audit.tls-skip-verify=trueso that plugin ingest also works over the self-signed connection.
Troubleshooting
| Symptom | What to check |
|---|---|
| Trino queries do not appear in audit | Confirm that the coordinator was restarted after installation. Confirm that the token in etc/event-listener.d/superna-audit.properties matches the current token. Rotating a token invalidates the old one. Confirm that the Trino host can reach the console URL. |
The install command prints ERROR: invalid token format | The token is not valid. A token contains only letters, digits, -, and _, and is often pasted with a stray character. Nothing was installed. Paste the token you saved and run the command again. If it is lost, generate or rotate one on this tab. Rotating replaces the token on every coordinator already installed. |
| Ingest returns 401 | The token is wrong or was rotated. Rotate the token on this tab and reinstall the plugin. |
| Install fails at Downloading plugin JAR, or with TLS or certificate errors | The console uses a self-signed certificate. See Console with a Self-Signed Certificate. |