Quarkus中如何拦截并按SIEM格式记录REST应用认证失败日志?
Absolutely, there are several reliable ways to intercept and log authentication/authorization failures in your Quarkus REST app, so you can format those logs for your SIEM system. Let’s walk through the most effective approaches, tailored to your needs:
1. Use Quarkus Native Security Event Listeners
This is the cleanest approach, as Quarkus emits dedicated security events for authentication and authorization failures that you can observe with a CDI bean. It lets you capture precise details without messing with filters or exception handlers.
Here's how to implement it:
- Create an application-scoped CDI bean that observes
AuthenticationFailedEvent(for 401s) andAuthorizationFailedEvent(for 403s). - Inject the
HttpServletRequestto pull request details like client IP, path, and HTTP method. - Format the log entry to match your SIEM's required schema.
Example code:
import io.quarkus.security.AuthenticationFailedEvent; import io.quarkus.security.AuthorizationFailedEvent; import jakarta.enterprise.context.ApplicationScoped; import jakarta.enterprise.event.Observes; import jakarta.inject.Inject; import jakarta.servlet.http.HttpServletRequest; import org.jboss.logging.Logger; @ApplicationScoped public class SecurityFailureLogger { private static final Logger LOG = Logger.getLogger(SecurityFailureLogger.class); @Inject HttpServletRequest request; // Handle 401 authentication failures public void logAuthFailure(@Observes AuthenticationFailedEvent event) { String clientIp = request.getRemoteAddr(); String requestPath = request.getRequestURI(); String httpMethod = request.getMethod(); String failureReason = event.getReason().orElse("Unknown authentication error"); // Format to your SIEM's required structure String siemLogEntry = String.format( "SIEM_EVENT: timestamp=%d, type=AUTH_FAILURE, client_ip=%s, http_method=%s, request_path=%s, reason=%s", System.currentTimeMillis(), clientIp, httpMethod, requestPath, failureReason ); LOG.error(siemLogEntry); } // Handle 403 authorization failures public void logAuthzFailure(@Observes AuthorizationFailedEvent event) { String clientIp = request.getRemoteAddr(); String requestPath = request.getRequestURI(); String httpMethod = request.getMethod(); String user = event.getSecurityIdentity().getPrincipal().getName(); String requiredRoles = event.getRoles().toString(); String siemLogEntry = String.format( "SIEM_EVENT: timestamp=%d, type=AUTHZ_FAILURE, client_ip=%s, http_method=%s, request_path=%s, user=%s, required_roles=%s", System.currentTimeMillis(), clientIp, httpMethod, requestPath, user, requiredRoles ); LOG.error(siemLogEntry); } }
This method integrates seamlessly with Quarkus's security pipeline, ensuring you capture every failure without gaps.
2. Use JAX-RS Exception Mappers
If you prefer working with JAX-RS constructs, you can create ExceptionMapper implementations to catch the exceptions that trigger 401/403 responses. This gives you direct control over logging when those exceptions are thrown.
For 401 (authentication failure):
import jakarta.ws.rs.NotAuthorizedException; import jakarta.ws.rs.core.Response; import jakarta.ws.rs.ext.ExceptionMapper; import jakarta.ws.rs.ext.Provider; import jakarta.inject.Inject; import jakarta.servlet.http.HttpServletRequest; import org.jboss.logging.Logger; @Provider public class NotAuthorizedExceptionMapper implements ExceptionMapper<NotAuthorizedException> { private static final Logger LOG = Logger.getLogger(NotAuthorizedExceptionMapper.class); @Inject HttpServletRequest request; @Override public Response toResponse(NotAuthorizedException exception) { // Build SIEM log entry String siemLogEntry = String.format( "SIEM_EVENT: timestamp=%d, type=AUTH_FAILURE, client_ip=%s, http_method=%s, request_path=%s, reason=%s", System.currentTimeMillis(), request.getRemoteAddr(), request.getMethod(), request.getRequestURI(), exception.getMessage() ); LOG.error(siemLogEntry); // Return the original 401 response to maintain app behavior return exception.getResponse(); } }
Repeat this pattern with a ForbiddenExceptionMapper to handle 403 authorization failures.
3. Customize Quarkus Logging Configuration (No-Code Option)
If you want a quicker setup without writing code, you can adjust Quarkus's logging settings to capture security-related events and format them for SIEM. Note that this is less flexible than the code-based approaches, but works for basic use cases.
Add these settings to your application.properties:
# Enable debug logging for Quarkus security components quarkus.log.category."io.quarkus.security".level=DEBUG quarkus.log.category."io.quarkus.vertx.http.access-log".level=INFO # Define a custom SIEM-compatible log format quarkus.log.console.format=SIEM_EVENT: timestamp=%d{UNIX_MILLIS}, type=SECURITY_FAILURE, client_ip=%X{remote-addr}, http_method=%X{method}, request_path=%X{path}, message=%m%n
This will log security-related events in a SIEM-friendly format, but you may need to tweak the pattern to include all the fields your SIEM requires.
Recommendation
I’d go with the Security Event Listener approach first—it’s Quarkus-native, captures precise failure details, and is easy to extend if you need to add more fields to your SIEM logs later.
内容的提问来源于stack exchange,提问作者Claus Radloff

