Tamper-Evident Audit Logs for Bacula — Now Included in Every faaleoleo Plan

Every faaleoleo managed Bacula deployment now ships with faaleoleo Log Audit — cryptographically signed, hash-chained audit logging for Bacula Enterprise — included at no extra cost, on every plan.

Bacula does not provide tamper-evident audit logs out of the box. Its own job history and syslog output record what happened, but neither can prove that the record has not been altered after the fact. For security audits, compliance reviews, and internal incident investigations, that gap is significant.

faaleoleo Log Audit closes it.

What the standards actually require

This is not a nice-to-have. Several frameworks that apply to organisations running backup infrastructure in the EU specifically require protected, verifiable audit records:

NIS2 (Article 21) requires essential and important entities to implement technical measures for monitoring, detecting, and responding to incidents — and to be able to demonstrate those measures were in effect. An audit log that can be silently edited does not satisfy this requirement.

GDPR (Article 5(2) and Article 32) places the burden of proof on the controller. If a data subject or supervisory authority asks you to demonstrate that backup access was controlled and that no unauthorised restore occurred, you need records that cannot be disputed.

DORA (Article 9 and Article 10) requires financial entities to maintain ICT event detection capabilities and to keep logs that support incident investigations. Regulators expect those logs to be trustworthy — that means tamper-evident, not just present.

ISO 27001:2022 (Control A.8.15) explicitly requires that event logs be "produced, stored, protected, and analysed." Protection means the log itself cannot be altered without detection.

Standard syslog and Bacula's native job database satisfy none of these protection requirements. They record events. They do not prove those events were not subsequently modified.

What faaleoleo Log Audit does

faaleoleo Log Audit runs alongside Bacula without modifying it. Every event — job completions, job failures, authentication attempts, configuration reloads, console connections — is written to a separate, append-only log file. Each entry is:

The result is a log where tampering — including deletion, reordering, insertion, or modification — is detectable by anyone holding the public key.

What an audit run looks like

An auditor — or your own security team — runs two commands: tail to inspect the log, verify to confirm nothing has been altered.

  ● [1038] 2026-06-21 01:00  info    scheduler  job_complete    NightlyFull / db01-fd
  ● [1039] 2026-06-21 01:04  info    scheduler  job_complete    NightlyFull / app01-fd
  ● [1040] 2026-06-21 01:09  error   scheduler  job_error       NightlyFull / legacy02-fd
  ● [1041] 2026-06-21 01:10  info    scheduler  job_complete    NightlyIncr / web01-fd
  ● [1042] 2026-06-21 08:32  warning system     auth_failure    192.168.1.71
  ● [1043] 2026-06-21 08:33  warning system     auth_failure    192.168.1.71
  ● [1044] 2026-06-21 09:15  info    ops-team   console_connect bacula-dir
  ● [1045] 2026-06-21 09:17  info    ops-team   config_reload   bacula-dir

● = entry carries a valid Ed25519 signature
✓ VERIFIED — 1,045 entries, chain intact, all signatures valid.
  Timespan: 2026-06-07T00:00:01.000000Z → 2026-06-21T09:17:33.112043Z

The public key is all the auditor needs — no access to the Bacula server, no faaleoleo account, no proprietary tooling.

Why this matters for security teams, not just auditors

Compliance is one reason. The other is operational: when something goes wrong, your security team needs a record they can trust.

If a backup job fails silently, a restore is performed outside normal procedure, or configuration is changed without approval, the audit log is the evidence. When that investigation reaches legal or insurance review — which it increasingly does after a breach — the question is not just what the log says but whether it can be trusted. A cryptographically verified chain answers that question definitively.

Internal SOC teams benefit equally. Authentication failures, unexpected console connections, and configuration reloads are all captured and signed. You can detect anomalies with confidence that the event record is accurate.

Included in every faaleoleo plan

faaleoleo Log Audit is not an add-on or an enterprise tier feature. It ships with every managed Bacula deployment we operate, configured and running from day one.

Every customer receives the public key for their installation at setup. Verification can be run at any time — by the customer, by an internal auditor, or by an external compliance reviewer — without any access to faaleoleo infrastructure.

This is the kind of audit capability that Bacula does not provide natively and that no other Bacula managed service includes by default.

If you are evaluating managed Bacula options and audit readiness is part of your requirements, talk to us.

The Backup Factory

See it for yourself

We are happy to walk you through exactly what the pipeline does and what the output looks like. No commitment required.

Talk to us