Skip to content

bifroest audit export

Verifies the signed committed journal state before writing JSON Lines in chain order. Bifröst can keep writing; later records are not included. The default view includes only name, optional domain and outcome, plus envelope metadata such as time and record ID. This applies to clear .baudit and encrypted .beaudit. Protect even redacted output. Export has bounded in-memory limits (including a 128 MiB output cap); use audit verify without materializing records for larger journals.

Use --with-sensitive to include confidential event fields. For .beaudit, this also requires the matching --decryptionIdentityFile and verifies the decrypted content. A redacted export of .beaudit needs no decryption identity. JSON Lines are an unsigned view, not a substitute for the original container.

Syntax

bifroest audit export [flags] [auditlogName]

Arguments

auditlogName selects one configured audit log by name and is required for local export. With --source, it is an optional output label, defaulting to default; use it for a non-default auditlog to preserve that name in exported JSONL. It is not a segment path. Remote sealed segments alone lack the signed head and cannot be exported with this command.

Flags

Includes all general flags.

--configuration

Optional configuration to load. Without this flag, local export uses the same platform default as bifroest run and its configured signing key as producer trust. Cannot be combined with --source; offline export needs no configuration file.

--source

Complete auditlog copy to read without a configuration file or signing private key, including the signed head and all segments. Requires --expectedProducerId from an independent trust source. A downloaded sealed segment alone is not a complete journal.

--encryptionPublicKeyFile

Expected encryption recipient for --source when reading a redacted encrypted journal without a private key, or when supplying multiple decryption identities. For a sensitive export with one --decryptionIdentityFile, the recipient is derived from that identity instead. Not used with the configured local journal.

--decryptionIdentityFile

Private SSH key required together with --with-sensitive for encrypted event fields. Repeat the flag when needed. Without --with-sensitive, supplied decryption identities are not loaded or used for the redacted export.

--with-sensitive

bool = false

Explicitly include confidential event fields in the JSON Lines output. This does not make the output encrypted; protect the destination accordingly.

--expectedProducerId

string

External trust anchor as a 64-hex producer ID. On the server, omit it to trust the configured signing key. With --source, it is required. Obtain the ID from the server's audit producer-id command and retain it through an independently trusted channel. An ID copied from the journal is not a trust anchor.

--output

File Path = "-"

Output file. - writes JSON Lines to stdout. The output file's immediate parent directory must already exist; the command does not create missing output directories. The parent is opened without following links where the platform supports it and remains pinned through the final safety check and atomic installation. Output paths inside any enabled configured journal or enabled recording repository, or aliasing a journal file, the loaded configuration file, a signing identity or a referenced encryption public-key file are rejected. Supplied decryption identities are also protected. When stdout is a regular file, the command rejects descriptors pointing to protected files, including journal heads and segments; normal pipes remain supported. Shell redirection with > can truncate a file before the command starts, so do not redirect stdout to protected files.

--force

bool = false

Replaces an existing output file.

Examples

Export redacted JSON Lines on the Bifröst host using the default configuration and audit log:

1
bifroest audit export default

Export a complete offline journal with an independently obtained producer ID, without a configuration or signing private key:

1
2
3
4
bifroest audit export \
  --source /srv/audit-evidence/auditlog \
  --expectedProducerId "<trusted-64-hex-id>" \
  --output /srv/audit-evidence/redacted.jsonl