Who changed this Keycloak setting? Turning on admin events
Keycloak does not record configuration changes by default. Here is how to turn on admin events, read them, and keep them from filling your database.
A client's redirect URIs changed, or a user suddenly has realm-admin, and nobody remembers doing it. Keycloak can tell you who did, but only if admin events were already switched on when it happened. They are off by default in every new realm.
What realmlint reports
MEDIUM Admin events are not saved [admin-events-disabled] - admin events are not saved LOW Login events are not saved [login-events-disabled] - user events are not saved
If admin events are on but Include representation is off, realmlint reports it as low: you can see who changed something, but not what they changed it to.
Turn on admin events
- Open the realm and go to Realm settings, then the Events tab.
- Open Admin events settings and turn on Save events.
- Turn on Include representation, so each event records the new configuration as well as the fact that it changed.
- Set an Expiration, for example 90 days, then click Save. Without one, events are kept forever in Keycloak's database.
- While you are there, open User events settings and turn on Save events for logins too, with its own expiration.
- Repeat for every realm, including master.
Read them
Go to Events in the left-hand menu and open the Admin events tab. Each event shows the time, the Resource path (for example clients/<id>), the Operation type (create, update or delete) and who made the change: the realm, client, user ID and IP address. With representation turned on, you can open the event to see the new configuration.
The event shows the user's ID rather than their username. Search for that ID under Users in the realm the admin logged in to, usually master.
Admin events only cover changes made through the admin console and admin REST API. Realms imported at startup, changes made directly in the database, and anything that happened before you switched them on are not recorded.
Fix it in a realm file
{
"realm": "myrealm",
"adminEventsEnabled": true,
"adminEventsDetailsEnabled": true,
"eventsEnabled": true,
"eventsExpiration": 7776000
}
eventsExpiration is in seconds and applies to user events. Set the admin events expiration in the admin console.
Check it worked
kc.sh export --realm myrealm --file myrealm.json realmlint check myrealm.json
To see what changed between two points in time, export again later and compare the two files:
realmlint diff myrealm-before.json myrealm-after.json
The diff tells you what changed. The admin events tell you who changed it.