I scrapped my logs from the past ~70 days (october, november and december logs) and found not a single audit failure with the following command: cat node.log | grep -i audit | grep -i fail
But this node was previously on a very slow SMR drive that was crawling miserably for hours (more than 10…) whenever watchtower would update it, making it slow to respond, so my best guess right now is that it might have failed an audit because of the 5 minute timeout in the past.
When an audit fails because of the timeout, is this audit failure supposed to be visible in the Node’s logs?
You can see the audit failed only for the first case. For the second case you could see only started audit but never finished. If the node was unresponsive or too slow or almost hang (but was able to answer on audit request), it might not even register the attempt, especially if that the same disk which the node is unable to read/write in a reasonable time.
Right, so I would need to parse the logs to (maybe) find started audits that do not have corresponding success/failure lines.
That would require some scripting
Thanks @Alexey.