Base solution for your next web application
Open Closed

AbpAuditLogs – Very High Performance Overhead / Is It Possible to Reduce or Disable Audit Logging? #12596


User avatar
0
pliaspzero created

V13.4 - Angular & ASPNET CORE 8

Hello Support Team,

we are currently operating a large ASP.NET Zero (ABP Framework, ASP.NET Core) production application and have identified significant performance overhead caused by AbpAuditLogs.

Observed behavior

AbpAuditLogs is written for almost every request, including:

Read-only API calls

Angular UI requests

High-frequency background operations

On high-load systems this results in:

Increased database write pressure

Noticeable latency impact

Large and fast-growing AbpAuditLogs table

In several performance traces, audit log inserts are among the top contributors to request execution time.

Our questions

Is it possible to completely disable audit logging via configuration? (e.g. appsettings.json or ABP settings)

Is there a supported way to limit audit logging to errors only? For example:

Only log failed requests

Only log exceptions

Disable logging for GET requests or specific controllers

Are there best practices or recommended configurations for high-throughput systems regarding audit logging?

If disabling globally is not recommended:

Is it possible to disable audit logging per module, per service, or per request?

Is there a lightweight alternative to full AbpAuditLogs for production environments?

Environment (summary)

ASP.NET Zero / ABP Framework

ASP.NET Core (.NET 8)

Angular frontend

High traffic, production workload

SQL Server backend

We would highly appreciate guidance on how to safely reduce or eliminate the audit logging overhead without breaking core ABP functionality.

Thank you very much in advance.

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @pliaspzero

    You're absolutely right. There are many practical ways to significantly reduce the workload in ASP.NET Zero projects.

    Below are supported and safe approaches, ordered from most common to most effective.

    Global switch (not recommended unless necessary)

    You can completely disable auditing globally, but this is usually not recommended unless you have an alternative monitoring strategy.

    YourProjectNameCoreModule.cs

    Configuration.Auditing.IsEnabled = false;
    

    However, this removes all audit logs (including security relevant ones).

    Disable Audit Logging Per Service / Method

    You can disable auditing at fine grained levels using attributes:

    [DisableAuditing]
    public async Task<List<ProductDto>> GetProductsAsync()
    {
        ...
    }
    

    This works for:

    • Application services
    • Controllers
    • Individual methods

    Periodic Audit Log Deletion

    ASP.NET Zero provides a built in background worker for this:

    Official docs: https://docs.aspnetzero.com/aspnet-core-mvc/latest/Features-Angular-Audit-Logs#periodic-log-deletion

    Example: appsettings.json

    "App": {
       "AuditLog": {
       "AutoDeleteExpiredLogs": {
         "IsEnabled": true,
         "ExcelBackup": {
           "IsEnabled": false,
           "FilePath": "App_Data/AuditLogsBackups/"
         }
       }
    }
    

    Selective Audit Logging Based on Severity

    Here's a recommended approach to implement selective audit logging by overriding the default behavior:

    Create a Custom Audit Store

    Create a new class that wraps the existing IAuditingStore implementation and filters which audit entries should be persisted:

    Example

    using Abp.Auditing;
    using Abp.Dependency;
    using Castle.Core.Logging;
    using Microsoft.AspNetCore.Mvc;
    using System.Linq;
    using System.Threading.Tasks;
    
    public class SelectiveAuditingStore : IAuditingStore, ITransientDependency
    {
        private readonly IAuditingStore _innerStore;
        private readonly ILogger _logger;
    
        public SelectiveAuditingStore(
            IAuditingStore innerStore,
            ILogger logger)
        {
            _innerStore = innerStore;
            _logger = logger;
        }
        
        public void Save(AuditInfo auditInfo)
        {
            _innerStore.Save(auditInfo);
        }
        public Task SaveAsync(AuditInfo auditInfo)
        {
            if (ShouldSaveAudit(auditInfo))
            {
                return _innerStore.SaveAsync(auditInfo);
            }
    
            return Task.CompletedTask;
        }
    
        private bool ShouldSaveAudit(AuditInfo auditInfo)
        {
            // Always log if there's an exception
            if (auditInfo.Exception != null)
            {
                return true;
            }
    
            // Exclude specific services (health checks, background jobs, etc.)
            var excludedServices = new[] 
            { 
                "HealthCheck", 
                "BackgroundJob",
                // Add your read only services here
            };
            
            if (excludedServices.Any(s => auditInfo.ServiceName?.Contains(s) == true))
            {
                return false;
            }
    
            // By default, log write operations (POST, PUT, DELETE)
            return true;
        }
    }
    

    Here you can disable GET methods or different method types if you wish, or you can control whether or not to write logs based on error codes.

    Register the Custom Store in Your Core Module

    In your YourProjectNameCoreModule.cs, add the following to the PreInitialize method:

    public override void PreInitialize()
    {
        // Keep auditing enabled but use our custom store
        Configuration.Auditing.IsEnabled = true;
        Configuration.Auditing.IsEnabledForAnonymousUsers = false;
        
    
        Configuration.ReplaceService<IAuditingStore, SelectiveAuditingStore>(
            DependencyLifeStyle.Transient);
    }
    

    Related Document

    We would be happy to help if you have any questions.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)