Deep-Drive Forensic Audit Logging

4 min read

BuildPiper
Advanced Audit
Forensics & Security

Deep-Drive Forensic Audit Logging #

For organisations requiring deeper forensic observability, BuildPiper provides an advanced audit logging mechanism that captures backend API activity at the request level — purpose-built for security investigations, root-cause analysis, and compliance evidence collection.

1. Forensic Audit Logging Overview #

For organisations requiring deeper forensic observability, BuildPiper provides an advanced Deep-Drive Forensic Audit Logging mechanism that goes beyond UI events to capture the underlying API interaction layer.

Important: This feature is not enabled by default and must be explicitly enabled from the BuildPiper UI before logs start accumulating.

What It Captures #

Once enabled, the forensic audit mechanism captures backend API activity at the HTTP method level — providing request-level visibility into actions being performed against the platform backend.

POST
All POST Requests

Every create/update API call made against the BuildPiper backend, with payload, user, and path.

DELETE
All DELETE Requests

Every destructive API call — captured with full attribution for forensic reconstruction.

BP Snapshot: Enabling Deep-Drive Forensic Audit Logging from the BuildPiper UI.

BP Snapshot: Enabling Deep-Drive Forensic Audit Logging from the BuildPiper UI settings

Unlike the standard UI audit logs, which focus primarily on operational events and user actions, this mechanism captures the underlying API interaction layer — making it suitable for forensic and security workflows.

Use Cases #

Security Incident Investigation

Reconstruct the chain of API events leading up to a suspected breach or anomaly.

Root-Cause Analysis

Pinpoint the exact request that caused an unexpected platform state change.

Operational Debugging

Detailed request-level visibility for troubleshooting complex operational issues.

Compliance Evidence

Tamper-evident logs of every destructive operation for regulatory audits.

API Activity Monitoring

Continuous visibility into how the platform backend is being used.

Unauthorized Action Investigation

Detect and analyse unauthorised or unexpected platform actions.

Incident Correlation

Correlate backend API operations with observed application or infrastructure incidents.

Log Storage Location #

The forensic audit logs are stored on the BuildPiper host at the following file system path:

Log File Path
/home/buildpiper/.log/buildpiper/audit_trail

Server-Level Access Required: These logs are not accessible via the BuildPiper UI. Reviewing or analysing them requires direct server-level access (SSH / file system access) to the BuildPiper host.

BP Snapshot: Forensic audit log directory on the BuildPiper host.

BP Snapshot: Forensic audit log directory layout on the BuildPiper host showing audit_trail file

How to Use the Forensic Audit Trail #

The Forensic Audit Trail is a powerful diagnostic tool for identifying security threats and reconstructing destructive events. The two most common use cases are illustrated below.

CASE 01
Detecting Unauthorised Access Attempts

If you suspect a malicious actor is attempting to compromise BuildPiper or executing a brute-force attack against specific user accounts, these logs provide the necessary telemetry for your analysis. The following log entry illustrates an unauthorised access attempt:

Audit Log Entry · Failed Login
[2026-05-26 15:36:57,113][130744095063904][views] User: Anonymous, Path: /api/v1/user/login/, Method: POST, Payload: {'email': 'user@example.com', 'password': ' [INFO]: UNAUTHORIZED : *********'}

What to look for: A high frequency of User: Anonymous entries against /api/v1/user/login/ with UNAUTHORIZED messages — especially from the same source — is a strong brute-force signal.

BP Snapshot: Unauthorised access attempt log sample.

BP Snapshot: Unauthorised access attempt log entry showing failed login POST request

CASE 02
Root-Cause Analysis for Unauthorised Resource Deletion

Another critical use case is root-cause analysis following unauthorised or accidental resource deletion. If a critical BuildPiper resource like a Kubernetes cluster suddenly disappears from your environment, you can use these logs to pinpoint exactly who initiated the action and when. The audit trail explicitly captures destructive operations.

Example A — Cluster deleted #

Audit Log Entries · Cluster DELETE
[2026-05-04 15:30:23,744][136328556460160][audit_trail][INFO]: User: samyak.jain@opstree.com, Path: /admin/api/v1/cluster/50/, Method: DELETE, Payload: {'entity_id': 50, 'name': 'cluster', 'label': 'cluster'}

[2026-05-04 15:33:51,792][136328557854784][audit_trail][INFO]: User: samyak.jain@opstree.com, Path: /admin/api/v1/cluster/51/, Method: DELETE, Payload: {'entity_id': 51, 'name': 'cluster', 'label': 'cluster'}

BP Snapshot: Cluster deletion audit log sample.

BP Snapshot: Cluster deletion audit log entries showing user and timestamp

Example B — Job Template deleted #

You can grep the audit log for specific destructive operations against a particular resource type. For job-template deletions:

Bash · Grep Job Template Deletions
cat audit.log.2026-05-02 | grep 'Method: DELETE' | grep 'template'
Audit Log Entries · Job Template DELETE
[2026-05-04 16:14:01,210][136328560115072][audit_trail][INFO]: User: sunny.kumar@mygurukulam.co, Path: /api/v1/project/72/job/template/1374/, Method: DELETE, Payload: {'entity_id': 1374, 'name': 'project_job_templates', 'label': 'job template'}, Message: job_template test with ID 1374 was deleted Successfully.

[2026-05-04 16:16:29,970][136328545178528][audit_trail][INFO]: User: sunny.kumar@mygurukulam.co, Path: /api/v1/job/template/1376/, Method: DELETE, Payload: {'entity_id': '1376', 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template test-V3 with ID 1376 was deleted Successfully.

[2026-05-11 11:08:55,652][136327890554528][audit_trail][INFO]: User: opstree@opstree.com, Path: /api/v1/job/template/1266/, Method: DELETE, Payload: {'entity_id': 1266, 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template Global-GOLANG-EXTENSIVE-CI with ID 1266 was deleted Successfully.

[2026-05-11 15:51:40,616][136327917204352][audit_trail][INFO]: User: aayush.verma@opstree.com, Path: /api/v1/job/template/1399/, Method: DELETE, Payload: {'entity_id': 1399, 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template Global-Global-olly-pr-update-ci with ID 1399 was deleted Successfully.
⚠ Audit Log Entry · ERROR Level
[2026-05-14 15:12:24,166][136328556460320][audit_trail][ERROR]: User: opstree@opstree.com, Path: /api/v1/job/template/1402/, Method: DELETE, Payload: {'entity_id': 1402, 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template Global-Testing with ID 1402 was deleted unsuccessfully.

Note the ERROR level entry: The forensic log preserves both successful and failed destructive attempts. Failed attempts ([ERROR]) are equally important — they may indicate unauthorised users without sufficient permissions probing the system.

BP Snapshot: Job template deletion audit log sample.

BP Snapshot: Job template deletion audit log entries showing multiple users and timestamps with one ERROR

Audit Capability Comparison #

A side-by-side comparison between the default UI audit trail and the deep-drive forensic audit logging mechanism.

Feature Default UI Audit Deep-Drive Forensic
Enabled by default YES NO
Requires explicit configuration NO YES
Accessible from BuildPiper UI YES NO
Captures resources: create / modify / delete YES YES
Tracks pod-level SSH access history YES NO
Captures backend API POST requests LIMITED YES
Captures backend API DELETE requests LIMITED YES
Suitable for operational audits YES YES
Suitable for forensic investigations MODERATE HIGH

BuildPiper Documentation · Deep-Drive Forensic Audit Logging

Last updated: May 2026