You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Quarkus中如何拦截并按SIEM格式记录REST应用认证失败日志?

Absolutely, there are several reliable ways to intercept and log authentication/authorization failures in your Quarkus REST app, so you can format those logs for your SIEM system. Let’s walk through the most effective approaches, tailored to your needs:

1. Use Quarkus Native Security Event Listeners

This is the cleanest approach, as Quarkus emits dedicated security events for authentication and authorization failures that you can observe with a CDI bean. It lets you capture precise details without messing with filters or exception handlers.

Here's how to implement it:

  • Create an application-scoped CDI bean that observes AuthenticationFailedEvent (for 401s) and AuthorizationFailedEvent (for 403s).
  • Inject the HttpServletRequest to pull request details like client IP, path, and HTTP method.
  • Format the log entry to match your SIEM's required schema.

Example code:

import io.quarkus.security.AuthenticationFailedEvent;
import io.quarkus.security.AuthorizationFailedEvent;
import jakarta.enterprise.context.ApplicationScoped;
import jakarta.enterprise.event.Observes;
import jakarta.inject.Inject;
import jakarta.servlet.http.HttpServletRequest;
import org.jboss.logging.Logger;

@ApplicationScoped
public class SecurityFailureLogger {

    private static final Logger LOG = Logger.getLogger(SecurityFailureLogger.class);

    @Inject
    HttpServletRequest request;

    // Handle 401 authentication failures
    public void logAuthFailure(@Observes AuthenticationFailedEvent event) {
        String clientIp = request.getRemoteAddr();
        String requestPath = request.getRequestURI();
        String httpMethod = request.getMethod();
        String failureReason = event.getReason().orElse("Unknown authentication error");

        // Format to your SIEM's required structure
        String siemLogEntry = String.format(
            "SIEM_EVENT: timestamp=%d, type=AUTH_FAILURE, client_ip=%s, http_method=%s, request_path=%s, reason=%s",
            System.currentTimeMillis(), clientIp, httpMethod, requestPath, failureReason
        );

        LOG.error(siemLogEntry);
    }

    // Handle 403 authorization failures
    public void logAuthzFailure(@Observes AuthorizationFailedEvent event) {
        String clientIp = request.getRemoteAddr();
        String requestPath = request.getRequestURI();
        String httpMethod = request.getMethod();
        String user = event.getSecurityIdentity().getPrincipal().getName();
        String requiredRoles = event.getRoles().toString();

        String siemLogEntry = String.format(
            "SIEM_EVENT: timestamp=%d, type=AUTHZ_FAILURE, client_ip=%s, http_method=%s, request_path=%s, user=%s, required_roles=%s",
            System.currentTimeMillis(), clientIp, httpMethod, requestPath, user, requiredRoles
        );

        LOG.error(siemLogEntry);
    }
}

This method integrates seamlessly with Quarkus's security pipeline, ensuring you capture every failure without gaps.

2. Use JAX-RS Exception Mappers

If you prefer working with JAX-RS constructs, you can create ExceptionMapper implementations to catch the exceptions that trigger 401/403 responses. This gives you direct control over logging when those exceptions are thrown.

For 401 (authentication failure):

import jakarta.ws.rs.NotAuthorizedException;
import jakarta.ws.rs.core.Response;
import jakarta.ws.rs.ext.ExceptionMapper;
import jakarta.ws.rs.ext.Provider;
import jakarta.inject.Inject;
import jakarta.servlet.http.HttpServletRequest;
import org.jboss.logging.Logger;

@Provider
public class NotAuthorizedExceptionMapper implements ExceptionMapper<NotAuthorizedException> {

    private static final Logger LOG = Logger.getLogger(NotAuthorizedExceptionMapper.class);

    @Inject
    HttpServletRequest request;

    @Override
    public Response toResponse(NotAuthorizedException exception) {
        // Build SIEM log entry
        String siemLogEntry = String.format(
            "SIEM_EVENT: timestamp=%d, type=AUTH_FAILURE, client_ip=%s, http_method=%s, request_path=%s, reason=%s",
            System.currentTimeMillis(),
            request.getRemoteAddr(),
            request.getMethod(),
            request.getRequestURI(),
            exception.getMessage()
        );

        LOG.error(siemLogEntry);

        // Return the original 401 response to maintain app behavior
        return exception.getResponse();
    }
}

Repeat this pattern with a ForbiddenExceptionMapper to handle 403 authorization failures.

3. Customize Quarkus Logging Configuration (No-Code Option)

If you want a quicker setup without writing code, you can adjust Quarkus's logging settings to capture security-related events and format them for SIEM. Note that this is less flexible than the code-based approaches, but works for basic use cases.

Add these settings to your application.properties:

# Enable debug logging for Quarkus security components
quarkus.log.category."io.quarkus.security".level=DEBUG
quarkus.log.category."io.quarkus.vertx.http.access-log".level=INFO

# Define a custom SIEM-compatible log format
quarkus.log.console.format=SIEM_EVENT: timestamp=%d{UNIX_MILLIS}, type=SECURITY_FAILURE, client_ip=%X{remote-addr}, http_method=%X{method}, request_path=%X{path}, message=%m%n

This will log security-related events in a SIEM-friendly format, but you may need to tweak the pattern to include all the fields your SIEM requires.

Recommendation

I’d go with the Security Event Listener approach first—it’s Quarkus-native, captures precise failure details, and is easy to extend if you need to add more fields to your SIEM logs later.

内容的提问来源于stack exchange,提问作者Claus Radloff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 11:22:34