Database audit log
This page describes how you can review the database audit log
ClickHouse provides database audit logs by default. This page focuses on security relevant logs. For more information on data recorded by the system, refer to the docs for system tables.
The system.query_log captures query activity executed in a ClickHouse instance. This information can be useful to determine what queries a threat actor executed.
Sample query to search for activities of a “compromised_account” user
Last modified on June 6, 2026