V13.4 - Angular & ASPNET CORE 8
Hello Support Team,
we are currently operating a large ASP.NET Zero (ABP Framework, ASP.NET Core) production application and have identified significant performance overhead caused by AbpAuditLogs.
Observed behavior
AbpAuditLogs is written for almost every request, including:
Read-only API calls
Angular UI requests
High-frequency background operations
On high-load systems this results in:
Increased database write pressure
Noticeable latency impact
Large and fast-growing AbpAuditLogs table
In several performance traces, audit log inserts are among the top contributors to request execution time.
Our questions
Is it possible to completely disable audit logging via configuration? (e.g. appsettings.json or ABP settings)
Is there a supported way to limit audit logging to errors only? For example:
Only log failed requests
Only log exceptions
Disable logging for GET requests or specific controllers
Are there best practices or recommended configurations for high-throughput systems regarding audit logging?
If disabling globally is not recommended:
Is it possible to disable audit logging per module, per service, or per request?
Is there a lightweight alternative to full AbpAuditLogs for production environments?
Environment (summary)
ASP.NET Zero / ABP Framework
ASP.NET Core (.NET 8)
Angular frontend
High traffic, production workload
SQL Server backend
We would highly appreciate guidance on how to safely reduce or eliminate the audit logging overhead without breaking core ABP functionality.
Thank you very much in advance.
1 Answer(s)
-
0
Hi @pliaspzero
You're absolutely right. There are many practical ways to significantly reduce the workload in ASP.NET Zero projects.
Below are supported and safe approaches, ordered from most common to most effective.
Global switch (not recommended unless necessary)
You can completely disable auditing globally, but this is usually not recommended unless you have an alternative monitoring strategy.
YourProjectNameCoreModule.cs
Configuration.Auditing.IsEnabled = false;However, this removes all audit logs (including security relevant ones).
Disable Audit Logging Per Service / Method
You can disable auditing at fine grained levels using attributes:
[DisableAuditing] public async Task<List<ProductDto>> GetProductsAsync() { ... }This works for:
- Application services
- Controllers
- Individual methods
Periodic Audit Log Deletion
ASP.NET Zero provides a built in background worker for this:
Official docs: https://docs.aspnetzero.com/aspnet-core-mvc/latest/Features-Angular-Audit-Logs#periodic-log-deletion
Example: appsettings.json
"App": { "AuditLog": { "AutoDeleteExpiredLogs": { "IsEnabled": true, "ExcelBackup": { "IsEnabled": false, "FilePath": "App_Data/AuditLogsBackups/" } } }Selective Audit Logging Based on Severity
Here's a recommended approach to implement selective audit logging by overriding the default behavior:
Create a Custom Audit Store
Create a new class that wraps the existing
IAuditingStoreimplementation and filters which audit entries should be persisted:Example
using Abp.Auditing; using Abp.Dependency; using Castle.Core.Logging; using Microsoft.AspNetCore.Mvc; using System.Linq; using System.Threading.Tasks; public class SelectiveAuditingStore : IAuditingStore, ITransientDependency { private readonly IAuditingStore _innerStore; private readonly ILogger _logger; public SelectiveAuditingStore( IAuditingStore innerStore, ILogger logger) { _innerStore = innerStore; _logger = logger; } public void Save(AuditInfo auditInfo) { _innerStore.Save(auditInfo); } public Task SaveAsync(AuditInfo auditInfo) { if (ShouldSaveAudit(auditInfo)) { return _innerStore.SaveAsync(auditInfo); } return Task.CompletedTask; } private bool ShouldSaveAudit(AuditInfo auditInfo) { // Always log if there's an exception if (auditInfo.Exception != null) { return true; } // Exclude specific services (health checks, background jobs, etc.) var excludedServices = new[] { "HealthCheck", "BackgroundJob", // Add your read only services here }; if (excludedServices.Any(s => auditInfo.ServiceName?.Contains(s) == true)) { return false; } // By default, log write operations (POST, PUT, DELETE) return true; } }Here you can disable GET methods or different method types if you wish, or you can control whether or not to write logs based on error codes.
Register the Custom Store in Your Core Module
In your
YourProjectNameCoreModule.cs, add the following to thePreInitializemethod:public override void PreInitialize() { // Keep auditing enabled but use our custom store Configuration.Auditing.IsEnabled = true; Configuration.Auditing.IsEnabledForAnonymousUsers = false; Configuration.ReplaceService<IAuditingStore, SelectiveAuditingStore>( DependencyLifeStyle.Transient); }Related Document
We would be happy to help if you have any questions.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)