{"id":19273,"date":"2026-09-09T15:44:59","date_gmt":"2026-09-09T19:44:59","guid":{"rendered":"https:\/\/www.iri.com\/blog\/?p=19273"},"modified":"2026-09-09T15:44:59","modified_gmt":"2026-09-09T19:44:59","slug":"iri-audit-log-wrangler-performance-security","status":"publish","type":"post","link":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/","title":{"rendered":"Wrangling IRI Logs for Speed &#038; Security Insights"},"content":{"rendered":"<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"74\" data-end=\"89\">Quick Overview<\/h2>\n<p data-start=\"91\" data-end=\"706\">IRI Audit Log Wrangler (ALW), introduced with the CoSort v11 Ops Governance System (OGS), extracts actionable information from the JSON audit logs generated by SortCL-compatible executions. Using SQL- and JSONPath-compatible query syntax in <code data-start=\"329\" data-end=\"335\">.ALW<\/code> scripts, CoSort users can analyze job performance and resource-control settings, while FieldShield and other SortCL users can audit sensitive-data handling, user activity, failures, and policy changes. Wrangler can also export filtered log data for reporting, analytics, graphing, or use in external log-analysis and SIEM platforms.<\/p>\n<p data-start=\"708\" data-end=\"1278\"><strong data-start=\"708\" data-end=\"721\">Abstract:<\/strong> This article provides practical examples of querying IRI audit logs with the Audit Log Wrangler (ALW) utility to extract actionable information. Sample ALW scripts show how <a href=\"https:\/\/www.iri.com\/products\/cosort\/overview\">IRI CoSort<\/a> users can wrangle log data to analyze job performance under different resource-control settings. Other examples show how <a href=\"https:\/\/www.iri.com\/products\/fieldshield\/overview\">IRI FieldShield<\/a> users can audit the treatment of sensitive data for compliance verification and incident tracing. The article also explains how an AI assistant can help build Wrangler scripts for your own queries.<\/p>\n<h2><strong>About Audit Log Wrangler<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">The <\/span><strong>Audit Log Wrangler <\/strong><span style=\"font-weight: 400;\">utility introduced within the <\/span><strong><a href=\"https:\/\/www.iri.com\/blog\/iri\/business\/whats-new-in-cosort-11\/\">CoSort v11<\/a> Ops Governance System (<a href=\"https:\/\/www.iri.com\/blog\/iri\/business\/introducing-the-iri-ops-governance-system-ogs\/\">OGS<\/a><\/strong><span style=\"font-weight: 400;\"><strong>)<\/strong> extracts information from JSON logs produced by <a href=\"https:\/\/www.iri.com\/products\/cosort\/sortcl\">SortCL<\/a>-compatible executions.\u00a0<\/span><\/p>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"1492\" data-end=\"1621\">SortCL scripts drive structured data integration, transformation, migration, cleansing, masking, and reporting jobs for users of:<\/p>\n<ul data-start=\"1623\" data-end=\"1696\">\n<li data-start=\"1623\" data-end=\"1635\">IRI CoSort<\/li>\n<li data-start=\"1636\" data-end=\"1653\">IRI FieldShield<\/li>\n<li data-start=\"1654\" data-end=\"1666\">IRI RowGen<\/li>\n<li data-start=\"1667\" data-end=\"1681\">IRI NextForm<\/li>\n<li data-start=\"1682\" data-end=\"1696\">IRI Voracity<\/li>\n<\/ul>\n<p>Designed for governors, auditors, and analysts, the command-line Wrangler utility parses and filters logs, generates reports, and exports delimited subsets of log data. One JSON audit log file is produced for each SortCL execution. <span id='easy-footnote-1-19273' class='easy-footnote-margin-adjust'><\/span><span class='easy-footnote'><a href='https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#easy-footnote-bottom-1-19273' title='&lt;span style=&quot;font-weight: 400;&quot;&gt;\u00a0&lt;\/span&gt;&lt;i&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Note that log files can be large and can contain information about job execution, permissions, statistics, resource control settings, performance, metadata aggregates, system information, information about data sources and targets (including data class, field, and function details specified for each), licensing details, and environment variables. See the OGS manual for the full log schema, and &lt;\/span&gt;&lt;\/i&gt;&lt;a href=&quot;https:\/\/www.iri.com\/blog\/data-transformation2\/controlling-the-growth-of-new-iri-audit-logs\/&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;this article&lt;\/span&gt;&lt;\/i&gt;&lt;\/a&gt;&lt;i&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt; on ways to control log file growth.'><sup>1<\/sup><\/a><\/span>\u00a0 <\/span><\/i>By extracting meaningful information from many detailed JSON audit logs, Wrangler helps organizations conduct security and compliance reviews and analyze job performance without requiring an external analytics platform. <span id='easy-footnote-2-19273' class='easy-footnote-margin-adjust'><\/span><span class='easy-footnote'><a href='https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#easy-footnote-bottom-2-19273' title='&lt;span style=&quot;font-weight: 400;&quot;&gt;\u00a0&lt;\/span&gt;&lt;i&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;You can also use Wrangler to extract the query results to delimited files suitable for analytics and graphing in tools like Excel. You can also export full IRI job logs directly, or the wrangled extracts, to more purpose-built log analytics and visualizing platforms and SIEM tools like Datadog and Splunk Enterprise Security.'><sup>2<\/sup><\/a><\/span><\/span><\/i><\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19285\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/IRI-Audit-Log-Wrangler-workflow-1.png\" alt=\"Audit Log Query &amp; Export workflow showing audit logs processed by a log query engine with JSONPath querying, filtering, and extraction, then exported to analytics tools, Excel, and SIEM or Splunk integration.\" width=\"491\" height=\"337\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/IRI-Audit-Log-Wrangler-workflow-1.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/IRI-Audit-Log-Wrangler-workflow-1-300x206.png 300w\" sizes=\"(max-width: 491px) 100vw, 491px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">This article demonstrates some of the insights you can generate from the Audit logs using the tool\u2019s SQL- and jQuery-compatible query syntax inside Audit Log Wrangler (.ALW) job scripts. It also explains how you can leverage the wrangler\u2019s JPath syntax support in AI assistants such as ChatGPT to create new log queries.<\/span><\/p>\n<h2><strong>Wrangler\u2019s Modes of Operation<\/strong><\/h2>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"3817\" data-end=\"3874\">Audit Log Wrangler offers two primary modes of operation:<\/p>\n<ol data-start=\"3876\" data-end=\"3927\">\n<li data-start=\"3876\" data-end=\"3899\">Interactive mode<\/li>\n<li data-start=\"3900\" data-end=\"3927\">Batch or script mode<\/li>\n<\/ol>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"3929\" data-end=\"3949\">Interactive Mode<\/h3>\n<p data-start=\"3951\" data-end=\"4028\">Interactive mode provides a user-friendly command-line interface that guides users through:<\/p>\n<ul data-start=\"4030\" data-end=\"4222\">\n<li data-start=\"4030\" data-end=\"4052\">Selecting audit logs<\/li>\n<li data-start=\"4053\" data-end=\"4117\">Defining query criteria using SQL- and JPath-compatible syntax<\/li>\n<li data-start=\"4118\" data-end=\"4151\">Displaying results in real time<\/li>\n<li data-start=\"4152\" data-end=\"4222\">Saving query specifications in an Audit Log Wrangler (<code data-start=\"4208\" data-end=\"4214\">.ALW<\/code>) script<\/li>\n<\/ul>\n<p data-start=\"4224\" data-end=\"4339\">The saved script can then be used for ad hoc or batch command-line execution.<\/p>\n<p data-start=\"4224\" data-end=\"4339\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19283\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Audit-log-wrangler-display-1-1024x427.png\" alt=\"IRI Interactive Audit Log Wrangler command-line interface showing the policy file, logs directory, log count, date range, and script options.\" width=\"657\" height=\"274\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Audit-log-wrangler-display-1-1024x427.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Audit-log-wrangler-display-1-300x125.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Audit-log-wrangler-display-1-768x320.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Audit-log-wrangler-display-1.png 1409w\" sizes=\"(max-width: 657px) 100vw, 657px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The interactive mode is ideal for exploratory analysis, debugging specific log entries, or quickly checking job performance statistics without needing to construct a formal script from scratch.<\/span><\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"4770\" data-end=\"4794\">Batch or Script Mode<\/h3>\n<p data-start=\"4796\" data-end=\"5054\">Batch mode supports command-line execution of existing ALW job scripts. Saving queries as <code data-start=\"4886\" data-end=\"4892\">.ALW<\/code> files makes it possible to repeat auditing tasks and integrate log analysis into enterprise compliance-reporting workflows.<\/p>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"5056\" data-end=\"5154\">Saved scripts can be run from the interactive mode or directly from the command line, for example:<br \/>\n<span style=\"background-color: #f2f4f5; color: #222222; font-family: Consolas, Monaco, monospace;\">$wrangler ssnaudit3.alw<\/span><\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19284\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/ALW-Script-Execution-Workflow-1024x494.png\" alt=\"Batch or Script Mode workflow showing an ALW script created interactively, manually, or with an AI assistant, saved as ssnaudit3.alw, executed with the $wrangler ssnaudit3.alw command, and used for repeatable audits and compliance reporting.\" width=\"550\" height=\"265\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/ALW-Script-Execution-Workflow-1024x494.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/ALW-Script-Execution-Workflow-300x145.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/ALW-Script-Execution-Workflow-768x370.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/ALW-Script-Execution-Workflow-730x350.png 730w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/ALW-Script-Execution-Workflow.png 1110w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The following ALW batch script examples were generated in the Wrangler interactive mode, manually, or by an AI assistant to demonstrate real-world performance and security audits.<\/span><\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"5412\" data-end=\"5468\">Speed and Performance Analysis with Audit Log Wrangler<\/h2>\n<p data-start=\"5470\" data-end=\"5674\">The performance examples below show how information captured in SortCL audit logs can be wrangled to compare memory settings, thread counts, block sizes, throughput, system load, and concurrent workloads.<\/p>\n<h3 data-start=\"5676\" data-end=\"5724\">Speed Example #1: Improving Memory Allocation<\/h3>\n<p data-start=\"5726\" data-end=\"6003\">Optimizing memory use where possible can improve system-wide performance when concurrent jobs are running. Incorrect settings can cause thrashing. This query helps identify an efficient <code data-start=\"5912\" data-end=\"5922\">cosortrc<\/code> memory value to use when large jobs run.<\/p>\n<pre>Policy_Location : [C:\\IRI\\cosort110\\etc\\Policy]\r\nLog_Location : [C:\\IRI\\cosort110\\logs]\r\n\r\nRange :\r\n[Audit-2026-05-20T09-50-48-002884-CUMULUS-sortcl.json,\r\nAudit-2026-05-20T16-28-01-018576-CUMULUS-sortcl.json]\r\n\r\nSeparator : \"\\t\"\r\nOut : [File,\"C:\\IRI\\cosort110\\MemoryUsageReport.out\"]\r\n\r\nHeader : \"JobName StartTime RAMrequested RecordsPerSecond MemoryUsed\"\r\n\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.execution.startTime]\r\nSelect : [$.statistics.resourceControlSettings.memoryMax]\r\nSelect : [$.statistics.performance.recsPerSecond]\r\nSelect : [$.statistics.performance.bufferMemoryUsed]\r\n\r\nWhere : [$[?(@.statistics.jobResults.recordsProcessed &gt; 50000000)]]<\/pre>\n<p>The resulting report includes:<\/p>\n<div style=\"overflow-x: auto;\">\n<pre>JobName                  StartTime            RAMrequested   RecordsPerSecond   MemoryUsed\r\n[\"CreditCard.scl\"]       2026-05-20T09:50:48  2970615808     1131913.063001     251658240\r\n[\"RAME_2000000.scl\"]     2026-05-20T09:52:12  3592421376     25948.006708       3592421376\r\n[\"CreditCard.scl\"]       2026-05-20T14:41:14  3084910592     364162.294909      41943040\r\n[\"CreditCard.scl\"]       2026-05-20T15:00:33  3276800000     1011127.474121     209715200\r\n[\"RAME_2000000.scl\"]     2026-05-20T15:02:05  3383754752     26105.924737       3383754750\r\n[\"CreditCard.scl\"]       2026-05-20T15:49:47  3308257280     975985.317549      167772160\r\n[\"RAME_2000000.scl\"]     2026-05-20T15:51:21  3020947456     25754.54004        3020947456\r\n[\"CreditCard.scl\"]       2026-05-20T16:00:37  3167748096     733094.278843      125829120\r\n[\"RAME_2000000.scl\"]     2026-05-20T16:02:33  3183476736     25833.214393      3183476736\r\n[\"CreditCard.scl\"]       2026-05-20T16:09:25  3382706176     431494.535735      83886080\r\n[\"RAME_2000000.scl\"]     2026-05-20T16:12:23  2915041280     25568.512393      2915041280\r\n[\"CreditCard.scl\"]       2026-05-20T16:19:16  2999975936     361469.066081      41943040\r\n[\"RAME_2000000.scl\"]     2026-05-20T16:22:44  3040870400     25860.772138      3040870400\r\n<\/pre>\n<\/div>\n<p>The query found the two largest jobs for analysis. Their different start times reveal differences in system conditions when they ran. In these results, the highest records-per-second value for the <code data-start=\"8175\" data-end=\"8191\">CreditCard.scl<\/code> job occurred when less memory was used.<\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"8273\" data-end=\"8335\">Speed Example #2: Correlating Performance with Thread Count<\/h3>\n<p data-start=\"8337\" data-end=\"8644\">Running the same representative job with different <code data-start=\"8388\" data-end=\"8400\">thread_max<\/code> settings in the <code data-start=\"8417\" data-end=\"8427\">cosortrc<\/code> file helps determine which setting performs best on a particular machine. The results can also help determine how many threads to license for CoSort on a given multi-core node.<\/p>\n<pre>Header : \"specFile systemLoadPercentage threadMax elapsedSeconds\"\r\nSeparator : \"\\t\"\r\nOut : [File,\"longtimes.txt\"]\r\n\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.statistics.performance.systemLoadPercentage]\r\nSelect : [$.statistics.resourceControlSettings.threadMax]\r\nSelect : [$.statistics.performance.elapsedSeconds]\r\n\r\nWhere : [$.execution.specFiles[?(@.name == 'sort5_4198.scl')]]<\/pre>\n<p>The displayed <code data-start=\"9057\" data-end=\"9072\">longtimes.txt<\/code> output was formatted with additional tabs for readability:<\/p>\n<pre>specFile              systemLoadPercentage   threadMax   elapsedSeconds\r\n[\"sort5_4198m.scl\"]   9                      1           62.12\r\n[\"sort5_4198m.scl\"]   25                     6           28.812\r\n[\"sort5_4198m.scl\"]   24                     5           29.419\r\n[\"sort5_4198m.scl\"]   24                     4           31.499\r\n[\"sort5_4198m.scl\"]   22                     3           31.235\r\n[\"sort5_4198m.scl\"]   14                     2           43.108\r\n[\"sort5_4198m.scl\"]   9                      1           62.316<\/pre>\n<p>The wrangled results above reveal that <code data-start=\"627\" data-end=\"644\">sort5_4198m.scl<\/code> achieved its fastest elapsed time of 28.812 seconds with 6 threads, despite the higher system load of 25%, and that performance scaled linearly as the thread count increased.<\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"9896\" data-end=\"9946\">Speed Example #3: Finding an Optimal Block Size<\/h3>\n<p data-start=\"9948\" data-end=\"10206\">This query helps identify an efficient I\/O setting in the resource-control file for a given job. Identifying I\/O bottlenecks can save substantial processing time when jobs read or write thousands of gigabytes each day.<\/p>\n<pre>Out : [File,\"C:\\IRI\\cosort110\\BlockSizeAnalysis.out\"]\r\nHeading : [AUTO]\r\n\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.execution.startTime]\r\nSelect : [$.statistics.resourceControlSettings.autoTune]\r\nSelect : [$.statistics.performance.recsPerSecond]\r\nSelect : [$.statistics.resourceControlSettings.blockSize]\r\n\r\nWhere : [$.execution.specFiles[?(@.name == 'CreditCard.scl')]]<\/pre>\n<p>Example results:<\/p>\n<pre>startTime             autoTune   recsPerSecond   blockSize\r\n2026-07-31T11:43:24   Off        629591.080797   139264\r\n2026-07-31T11:44:26   Off        663350.248756   220000\r\n2026-07-31T11:45:01   Off        662910.507126   440000\r\n2026-07-31T12:11:31   On         669942.273336   614400\r\n2026-07-31T12:23:24   Off        685010.046809   1320000\r\n2026-07-31T12:29:45   Off        694846.902142   1640000\r\n2026-07-31T12:34:14   Minimize   668822.093412   139264<\/pre>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"11080\" data-end=\"11206\">The report also includes the <code data-start=\"11109\" data-end=\"11119\">cosortrc<\/code> value for <strong data-start=\"11130\" data-end=\"11142\">AutoTune<\/strong>, which configures memory and block size dynamically at runtime.<\/p>\n<p data-start=\"11208\" data-end=\"11240\">According to the source article:<\/p>\n<ul data-start=\"11242\" data-end=\"11434\">\n<li data-start=\"11242\" data-end=\"11288\"><code data-start=\"11244\" data-end=\"11248\">On<\/code> is usually best for jobs running alone.<\/li>\n<li data-start=\"11289\" data-end=\"11332\"><code data-start=\"11291\" data-end=\"11301\">Minimize<\/code> is intended for multiple jobs.<\/li>\n<li data-start=\"11333\" data-end=\"11434\"><code data-start=\"11335\" data-end=\"11340\">Off<\/code> indicates that memory and block-size values were explicitly specified in the <code data-start=\"11418\" data-end=\"11428\">cosortrc<\/code> file.<\/li>\n<\/ul>\n<p data-start=\"11436\" data-end=\"11591\">In this test, the highest measured throughput for <code data-start=\"11486\" data-end=\"11502\">CreditCard.scl<\/code> was associated with a block size of <strong data-start=\"11539\" data-end=\"11550\">1.64 MB<\/strong>.<\/p>\n<p data-start=\"11593\" data-end=\"11701\">For broader tuning across multiple jobs, the <code data-start=\"11638\" data-end=\"11645\">Where<\/code> filter can be removed and job name added to the output:<\/p>\n<pre>Header : \"JobName StartTime ElapsedTime RecordsPerSecond BlockSize\"\r\n\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.execution.startTime]\r\nSelect : [$.statistics.performance.elapsedTime]\r\nSelect : [$.statistics.performance.recsPerSecond]\r\nSelect : [$.statistics.resourceControlSettings.blockSize]\r\nSelect : [$.statistics.performance.systemLoadPercentage]<\/pre>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"12201\" data-end=\"12258\">Speed Example #4: Identifying the Least Efficient Jobs<\/h3>\n<p data-start=\"12260\" data-end=\"12640\">The records-per-second value recorded with each SortCL execution can be used to isolate performance bottlenecks. This example identifies jobs that meet a specified low-throughput threshold. Administrators can then examine the resource settings used by those jobs and determine what else may have been running on the system at the same time.<\/p>\n<pre>Heading : [AUTO]\r\nSeparator : \"\\t\"\r\nOut : [File,\"slowThroughPut1.txt\"]\r\n\r\nSelect : [$.statistics.performance.recsPerSecond]\r\nWhere : [$[?(@.statistics.performance.recsPerSecond &lt;= 30000)]]\r\nSelect : [$.execution.commandLine]\r\nSelect : [$.statistics.jobResults.recordsProcessed]\r\nSelect : [$.statistics.performance.systemLoadPercentage]\r\nSelect : [$.statistics.resourceControlSettings.threadMax]<\/pre>\n<p>Example output:<\/p>\n<pre>recsPerSecond   jobName                  recordsProcessed   systemLoadPercentage   threadMax\r\n1612.903226     [\"sort5_4198m.scl\"]      100                14                     4\r\n16949.152542    [\"sort5_4198m.scl\"]      1000               12                     4\r\n25759.156302    [\"Replacer200.scl\"]      12000006           11                     4<\/pre>\n<p>Another approach is to isolate jobs exceeding an elapsed-time threshold:<\/p>\n<pre>Select : [$.execution.commandLine]\r\nSelect : [$.statistics.performance.elapsedSeconds]\r\nWhere : [$[?(@.statistics.performance.elapsedSeconds &gt;=100)]]<\/pre>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"13695\" data-end=\"13760\">Speed Example #5: Detecting Job Slowdowns from Concurrent Workloads<\/h3>\n<p data-start=\"13762\" data-end=\"14134\">This query can help identify system bottlenecks caused by other jobs starting while a SortCL job is already running. If these overlaps are not addressed, they can result in unnecessary slowdowns. The system load percentage recorded in the log can indicate that another job began during the SortCL execution, while the start time lets you compare other job or system logs to determine what was running concurrently.<\/p>\n<pre>Header : \"ScriptName StartTime RecordsPerSecond SystemLoadPercentage\"\r\n\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.execution.startTime]\r\nSelect : [$.statistics.performance.recsPerSecond]\r\nSelect : [$.statistics.systemInfo.systemLoadPercentage]<\/pre>\n<p>The example results compare two jobs running separately on one day and concurrently the next:<\/p>\n<pre>ScriptName                StartTime              RecordsPerSecond   SystemLoadPercentage\r\n[\"CUSTOMERS_14F.SCL\"]     2026-07-29 14:14:47    606857.793062      18\r\n[\"ENCRYPT_SSN.scl\"]       2026-07-29 16:15:00    153830.769231      10\r\n[\"CUSTOMERS_14F.SCL\"]     2026-07-30 14:15:28    583998.73467       21\r\n[\"ENCRYPT_SSN.scl\"]       2026-07-30 14:15:31    143389.101338      27<\/pre>\n<p><span style=\"font-weight: 400;\">This query can also help a system administrator quickly identify patterns such as:<\/span><\/p>\n<ul>\n<li data-start=\"14935\" data-end=\"15051\"><strong data-start=\"14937\" data-end=\"15008\">Same job + lower <code data-start=\"14956\" data-end=\"14974\">RecordsPerSecond<\/code> + higher <code data-start=\"14984\" data-end=\"15006\">SystemLoadPercentage<\/code><\/strong> \u2192 likely contention from another workload.<\/li>\n<li data-start=\"15052\" data-end=\"15145\"><strong data-start=\"15054\" data-end=\"15115\">Same job + consistently low throughput regardless of load<\/strong> \u2192 likely SortCL tuning issue.<\/li>\n<li data-start=\"15146\" data-end=\"15278\"><strong data-start=\"15148\" data-end=\"15201\">High system load only during certain time windows<\/strong> \u2192 possible scheduled-application interference or overlapping batch activity.<\/li>\n<\/ul>\n<p>The log element <code data-start=\"15296\" data-end=\"15331\">$.statistics.jobResults.processID<\/code> may also be useful when correlating a SortCL execution with operating-system-level monitoring tools.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19288\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/image3-1024x560.png\" alt=\"\" width=\"896\" height=\"490\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/image3-1024x560.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/image3-300x164.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/image3-768x420.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/image3.png 1110w\" sizes=\"(max-width: 896px) 100vw, 896px\" \/><\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"15479\" data-end=\"15519\">Security and Compliance Audit Examples<\/h2>\n<p data-start=\"15521\" data-end=\"15683\">Audit Log Wrangler can also extract information useful for security review, compliance verification, incident tracing, access analysis, and OGS policy monitoring.<\/p>\n<h3 data-start=\"15685\" data-end=\"15742\">Security Example #1: Tracing Jobs by User and Time<\/h3>\n<p>This example helps determine who accessed particular data at a particular time, supporting investigation against company role-based access control (RBAC) and zero-trust\/non-repudiation policies.<b><\/b><\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19290\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs-1024x375.png\" alt=\"Workflow showing a user, SortCL job, start time, and audit log leading to security and compliance review.\" width=\"563\" height=\"206\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs-1024x375.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs-300x110.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs-768x281.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs-1536x562.png 1536w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs-2048x750.png 2048w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/tracing-jobs.png 1110w\" sizes=\"(max-width: 563px) 100vw, 563px\" \/><\/p>\n<pre># Author: sidewind\r\n# Written: [2026-07-07T13-32-42]\r\n\r\nPolicy_Location : [C:\\IRI\\cosort110\\etc\\Policy]\r\nLog_Location : [C:\\IRI\\cosort110\\logs]\r\n\r\nRange :\r\n[Audit-2026-05-13T16-41-07-018360-CUMULUS-sortcl.json,\r\nAudit-2026-05-13T17-02-58-018364-CUMULUS-sortcl.json]\r\n\r\nHeading : [AUTO]\r\nSeparator : \"\\t\"\r\nOut : [File,\"nametest.txt\"]\r\n\r\nSelect : [$.execution.username]\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.execution.startTime]\r\nSelect : [logFileName]<\/pre>\n<p>When the script runs in Wrangler interactive mode or from the command line, results can appear on screen or be written to a delimited file such as:<\/p>\n<pre><span style=\"font-weight: 400;\">username   name                      startTime              LogFileName\r\nsusan      [\"sort5_4198m.scl\"]       2026-05-13T16:41:07    Audit-2026-05-13T16-41-07-018360-CUMULUS-sortcl.json\r\nsusan      [\"sort5_4198m.scl\"]       2026-05-13T16:44:57    Audit-2026-05-13T16-44-40-018360-CUMULUS-sortcl.json\r\ndavid      [\"repli_2000000.scl\"]     2026-05-13T16:57:56    Audit-2026-05-13T16-57-56-018441-CUMULUS-sortcl.json\r\njorge      [\"aggregate2.scl\"]        2026-05-13T17:02:58    Audit-2026-05-13T17-02-58-018593-CUMULUS-sortcl.json\r\n<\/span><\/pre>\n<p>With <code data-start=\"17137\" data-end=\"17155\">Heading : [AUTO]<\/code>, the displayed header contains only the final log-schema element. A custom header can be specified instead, as shown in later examples.<\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"17333\" data-end=\"17385\">Security Example #2: Finding Jobs That Access PII<\/h2>\n<p class=\"\" data-start=\"17387\" data-end=\"17531\">This query helps manage data-breach and compliance risk by identifying jobs and data sources in which a specified sensitive field was processed.<\/p>\n<p data-start=\"17533\" data-end=\"17600\">The example searches specifically for the <code data-start=\"17575\" data-end=\"17593\">PolicyHolder_SSN<\/code> field:<\/p>\n<pre>Separator : \"\\t\"\r\nOut : [File,\"c:\\IRI\\cosort110\\logs\\Job11.out\"]\r\n\r\nHeader : \"JobName SourceName(s) FieldName\"\r\n\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.statistics.dataSources[*].name]\r\nSelect : [$.statistics.dataSources[*].fieldInfo[?(@.name == 'PolicyHolder_SSN')].name]\r\n\r\nWhere : [$.statistics.dataSources[*].fieldInfo[?(@.name == 'PolicyHolder_SSN')]]<\/pre>\n<p>Example output:<\/p>\n<pre>JobName                SourceName(s)             FieldName\r\n[\"sort5_4198m.scl\"]    [\"BIG2\",\"BIG3\",\"BIG4\"]   [\"PolicyHolder_SSN\"]\r\n[\"sort5_4198m.scl\"]    [\"BIG2\",\"BIG3\",\"BIG4\"]   [\"PolicyHolder_SSN\"]\r\n[\"sort6_4198m.scl\"]    [\"BIG2\",\"BIG3\",\"BIG4\"]   [\"PolicyHolder_SSN\"]\r\n[\"sort6_4198m.scl\"]    [\"BIG2\",\"BIG3\",\"BIG4\"]   [\"PolicyHolder_SSN\"]<\/pre>\n<p>In this case, <code data-start=\"18357\" data-end=\"18375\">PolicyHolder_SSN<\/code> was processed in two SortCL jobs, each of which ran twice.<\/p>\n<p>The article intentionally abbreviates the top portions of this and subsequent Wrangler scripts for space and shows only the relevant <code data-start=\"18569\" data-end=\"18577\">Select<\/code> and <code data-start=\"18582\" data-end=\"18589\">Where<\/code> queries needed to produce the results.<\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"18759\" data-end=\"18830\">Security Example #3: Detecting Permission Violations and Failed Jobs<\/h2>\n<p data-start=\"18832\" data-end=\"19069\">This ALW script identifies SortCL jobs that failed for any reason, including attempts to execute on an unlicensed hostname or failures caused by user access restrictions defined in the Policy File.<\/p>\n<pre>Separator : \"\\t\"\r\nOut : [File,\"C:\\IRI\\cosort110\\BlockedJobs.out\"]\r\n\r\nHeader : \"StartTime User JobName ReturnCode ErrorMessage\"\r\n\r\nSelect : [$.execution.startTime]\r\nSelect : [$.execution.username]\r\nSelect : [$.execution.specFiles[*].name]\r\nSelect : [$.statistics.jobResults.returnCode]\r\nSelect : [$.statistics.jobResults.errorMessage]\r\n\r\nWhere : [$[?(@.statistics.jobResults.successfulCompletion == false)]]<\/pre>\n<p>The result in the <code data-start=\"19484\" data-end=\"19501\">BlockedJobs.out<\/code> file can contain entries such as:<\/p>\n<pre>StartTime              User    JobName                 ReturnCode   ErrorMessage\r\n2026-05-10T10:14:37    joker   [\"Group1000.scl\"]       46           license violation: incorrect node or invalid key\r\n2026-05-12T14:32:18    polly   [\"ClaimMasking.scl\"]    210          Permission Denied\r\n2026-05-20T11:47:05    ethan   [\"CustExtract.scl\"]     46           license violation: incorrect node or invalid key\r\n2026-05-20T13:08:54    susan   [\"PolicyReport.scl\"]    210          Permission denied\r\n2026-05-20T15:26:41    joker   [\"Group1000.scl\"]       46           license violation: incorrect node or invalid key<\/pre>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"20156\" data-end=\"20345\">For <strong data-start=\"20160\" data-end=\"20172\">error 46<\/strong>, the source article specifies examining the hostname in the log and sending IRI the contents of <code data-start=\"20269\" data-end=\"20282\">RegForm.txt<\/code> and the machine&#8217;s <code data-start=\"20301\" data-end=\"20313\">cosort.lic<\/code> file to determine the mismatch.<\/p>\n<p data-start=\"20347\" data-end=\"20611\">For <strong data-start=\"20351\" data-end=\"20382\">error 210 Permission Denied<\/strong>, the governor should examine the user and job name (<code data-start=\"20435\" data-end=\"20441\">.scl<\/code> script) against the active Policy File. The PFM utility can show that user&#8217;s permissions for the job script&#8217;s elements, or forms.<\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"20613\" data-end=\"20665\">Security Example #4: Spotting Policy File Changes<\/h2>\n<p data-start=\"20667\" data-end=\"20849\">This report supports change tracking and non-repudiation by monitoring modifications to the <a href=\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-ogs-policy-file-runtime-governance\/\"><strong data-start=\"20759\" data-end=\"20808\">IRI Operational Governance System (OGS) Policy File<\/strong><\/a>.<\/p>\n<pre>Separator : \"\\t\"\r\nOut : [File,\"c:\\iri\\cosort110\\polmod.out\"]\r\n\r\nSelect : [$.execution.username]\r\nSelect : [$.execution.startTime]\r\nSelect : [$.execution.commandLine]\r\nSelect : [$.execution.policy.whenModified]<\/pre>\n<p>Selected <code data-start=\"21077\" data-end=\"21089\">polmod.out<\/code> results:<\/p>\n<pre>...\r\nsusan   2026-05-20T16:22:29   sortcl \/spec=example37.scl         2026-02-23T19:19:35\r\nsusan   2026-05-21T16:22:29   sortcl \/spec=Group1000.scl         2026-02-23T19:19:35\r\nsusan   2026-05-21T16:22:29   sortcl \/spec=example21.scl         2026-02-23T19:19:35\r\n...\r\nsusan   2026-05-26T12:44:44   sortcl \/spec=R_NAME_2000000.scl    2026-02-25T11:04:15\r\nsusan   2026-05-26T13:27:54   sortcl \/spec=SORT_NAME_2000000.scl 2026-02-25T11:04:15\r\nsusan   2026-05-26T13:22:03   sortcl \/spec=SORT_NAME_10000.scl   2026-02-25T11:04:15\r\nsusan   2026-05-26T14:27:38   sortcl \/spec=SORT_NAME_20.scl      2026-02-25T11:04:15<\/pre>\n<p>When the report identifies a Policy File change, security officers can investigate PFM utility archives or Policy File change logs to determine exactly what policy changed, when the change occurred, and which OGS administrator, or <strong data-start=\"21947\" data-end=\"21959\">governor<\/strong>, made it.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19291\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes-1024x375.png\" alt=\"Workflow showing a policy file change being detected, traced to a user and timestamp, recorded in an audit log, and reviewed for security and compliance. \" width=\"596\" height=\"218\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes-1024x375.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes-300x110.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes-768x281.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes-1536x563.png 1536w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes-2048x750.png 2048w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/Tracking-Policy-File-Changes.png 1110w\" sizes=\"(max-width: 596px) 100vw, 596px\" \/><\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"22359\" data-end=\"22396\"><span role=\"text\">Using AI to Generate ALW Scripts<\/span><\/h2>\n<p data-start=\"22398\" data-end=\"22815\">Because IRI OGS logs are stored in JSON and Wrangler parses them with JPath syntax, AI assistants such as ChatGPT, Claude, Copilot, and Gemini can help generate new queries. Users can describe the desired query in natural language and provide the AI assistant with enough information about the audit-log structure and Wrangler syntax to construct a corresponding <code data-start=\"22761\" data-end=\"22767\">.ALW<\/code> script.<\/p>\n<p>You will need to provide the AI engine with the log structure and specific requirements to build the script. A full sample log file, together with a representative ALW script from this article or the Wrangler section of the OGS manual that includes a <code>SELECT<\/code> and <code>WHERE<\/code> clause, should provide sufficient context.<\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"23219\" data-end=\"23269\">Workflow for Getting AI Help with an ALW Script<\/h3>\n<ol>\n<li data-start=\"23271\" data-end=\"23292\"><strong>Gather Context: <\/strong>Collect a sample JSON audit log file or the relevant audit-log schema from the OGS manual, so the AI assistant can understand the data format.<\/li>\n<li data-start=\"23271\" data-end=\"23292\"><strong>Formulate the Request: <\/strong>Write a clear, descriptive prompt defining the goal of the audit.<\/li>\n<li data-start=\"23271\" data-end=\"23292\"><strong>Specify the Required Format: <\/strong>Tell the AI assistant to return the script using the specific <code data-start=\"23632\" data-end=\"23640\">SELECT<\/code> and <code data-start=\"23645\" data-end=\"23652\">WHERE<\/code> syntax required by Wrangler.<\/li>\n<\/ol>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"23723\" data-end=\"23752\">Example AI Prompt Template<\/h3>\n<p data-start=\"23754\" data-end=\"23813\">You can adapt the following template to the query you need:<\/p>\n<p><i><span style=\"font-weight: 400;\">&#8220;I need to generate an IRI OGS Audit Log Wrangler (.alw) script. Here is a sample script: [Paste one here] and sample IRI OGS audit log from a SortCL job:\u00a0 [Upload or paste a sample log file or its schema here].<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">Please create an .alw script that performs the following action: [Describe your goal, e.g., &#8216;Find all jobs where the user is &#8216;susan&#8217; and the job result was unsuccessful&#8217;].<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">Use the following Wrangler syntax guidelines:<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">&#8211;\u00a0 Use &#8216;SELECT : [JPath]&#8217; for fields.<br \/>\n<\/span><\/i><i><span style=\"font-weight: 400;\">&#8211;\u00a0 Use &#8216;WHERE : [JPath condition]&#8217; for filtering.<br \/>\n<\/span><\/i><i><span style=\"font-weight: 400;\">&#8211;\u00a0 Include standard headers like Policy_Location and Log_Location as placeholders.<br \/>\n<\/span><\/i><i><span style=\"font-weight: 400;\">&#8211;\u00a0 Include today\u2019s date in the comments and use a default or custom header as shown.<br \/>\n<\/span><\/i><i><span style=\"font-weight: 400;\">&#8211;\u00a0 Specify a logical name for the tab-separated [or other-separated] output file&#8221;<\/span><\/i><\/p>\n<h3><b>Key Elements to Include in Your Scripts<\/b><\/h3>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"24770\" data-end=\"24900\">When reviewing an ALW script generated by an AI assistant, verify that it contains the components used in successful <code data-start=\"24887\" data-end=\"24893\">.ALW<\/code> files:<\/p>\n<ul data-start=\"24902\" data-end=\"25478\">\n<li data-start=\"24902\" data-end=\"25073\"><strong data-start=\"24904\" data-end=\"24934\">Script header information:<\/strong> Policy File path and filename, log-folder location, log-date range, output filename for the extract, and delimiter character or separator.<\/li>\n<li data-start=\"25074\" data-end=\"25210\"><strong data-start=\"25076\" data-end=\"25101\">Output header format:<\/strong> <code data-start=\"25102\" data-end=\"25120\">Heading : [AUTO]<\/code> uses the final element in the JSON key name unless a custom header is provided in quotes.<\/li>\n<li data-start=\"25211\" data-end=\"25344\"><strong data-start=\"25213\" data-end=\"25229\">Query logic:<\/strong> <code data-start=\"25230\" data-end=\"25238\">SELECT<\/code> statements identify fields to display, while a <code data-start=\"25286\" data-end=\"25293\">WHERE<\/code> clause filters for a condition using JPath syntax.<\/li>\n<li data-start=\"25345\" data-end=\"25478\"><strong data-start=\"25347\" data-end=\"25360\">Comments:<\/strong> Lines beginning with <code data-start=\"25382\" data-end=\"25385\">#<\/code> can document the script&#8217;s purpose, author, and date.<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">By providing the schema and a clearly defined query goal, you can map your requirements to Wrangler&#8217;s JPath query capabilities and produce a fit-for-purpose <code data-start=\"25637\" data-end=\"25643\">.ALW<\/code> job script.<\/span><\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" data-start=\"25702\" data-end=\"25707\">FAQ<\/h2>\n<h3 data-start=\"25709\" data-end=\"25748\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-19293 alignright\" src=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/faq-1024x673.png\" alt=\"\" width=\"244\" height=\"160\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/faq-1024x673.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/faq-300x197.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/faq-768x505.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/faq.png 1110w\" sizes=\"(max-width: 244px) 100vw, 244px\" \/><\/h3>\n<h3 data-start=\"25709\" data-end=\"25748\">What does IRI Audit Log Wrangler do?<\/h3>\n<p data-start=\"25750\" data-end=\"26064\">Audit Log Wrangler extracts information from the JSON audit logs generated by SortCL-compatible executions. It can parse, filter, report on, and export selected log information for performance analysis, security review, compliance auditing, and related operational analysis.<\/p>\n<h3 data-start=\"26066\" data-end=\"26127\">What is the difference between interactive and batch mode?<\/h3>\n<p data-start=\"26129\" data-end=\"26429\">Interactive mode guides the user through selecting logs, defining query criteria, viewing results, and saving an ALW script. Batch mode executes previously saved <code data-start=\"26291\" data-end=\"26297\">.ALW<\/code> scripts from the command line and is suitable for repeatable audit and reporting workflows.<\/p>\n<h3 data-start=\"26431\" data-end=\"26493\">Can Audit Log Wrangler help identify jobs that process PII?<\/h3>\n<p data-start=\"26495\" data-end=\"26750\">Yes. The article demonstrates an ALW script that searches audit-log metadata for a specified sensitive field\u2014in the example, <code data-start=\"26620\" data-end=\"26638\">PolicyHolder_SSN<\/code>\u2014and reports the SortCL job and source names associated with that field.<\/p>\n<h3 data-start=\"26752\" data-end=\"26813\">Can Audit Log Wrangler help diagnose performance problems?<\/h3>\n<p data-start=\"26815\" data-end=\"27081\">Yes. The examples in this article use logged information such as memory allocation, thread count, records per second, block size, elapsed time, and system load to compare job executions and investigate performance differences.<\/p>\n<h3 data-start=\"27083\" data-end=\"27140\">Can AI assistants generate Audit Log Wrangler scripts?<\/h3>\n<p data-start=\"27142\" data-end=\"27441\">The article describes using AI assistants to help generate <code data-start=\"27201\" data-end=\"27207\">.ALW<\/code> scripts when they are given the audit-log schema or a representative log, an example Wrangler script, the desired query, and instructions for using Wrangler&#8217;s JPath <code data-start=\"27373\" data-end=\"27381\">SELECT<\/code> and <code data-start=\"27386\" data-end=\"27393\">WHERE<\/code> syntax.<\/p>\n<h2><b>Summary<\/b><\/h2>\n<p>Audit Log Wrangler is a companion to the OGS audit-logging framework that converts raw JSON job logs into requested information for <strong data-start=\"27590\" data-end=\"27666\">compliance, data security, performance tuning, and operational oversight<\/strong>.<\/p>\n<p><span style=\"font-weight: 400;\">Wrangler uses targeted filtering, secure sharing, and structured reporting to help organizations make full use of the rich metadata in OGS without being overwhelmed by its volume or complexity. Wrangler&#8217;s JPath query support also makes it possible to provide an AI assistant with a representative audit log or schema, a sample <code data-start=\"28150\" data-end=\"28156\">.ALW<\/code> script, and a description of the desired query so that the assistant can help construct another ALW script.<\/span><\/p>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"28266\" data-end=\"28555\">Together with the Policy File, PFM utility, and script signature system, Wrangler forms part of the operational governance environment for SortCL-driven jobs in IRI CoSort, FieldShield, NextForm, RowGen, and Voracity production environments.<\/p>\n<p data-start=\"28557\" data-end=\"28683\">For questions or assistance using IRI Audit Log Wrangler, contact <a href=\"mailto:support@iri.com\"><span style=\"font-weight: 400;\">support@iri.com<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quick Overview IRI Audit Log Wrangler (ALW), introduced with the CoSort v11 Ops Governance System (OGS), extracts actionable information from the JSON audit logs generated by SortCL-compatible executions. Using SQL- and JSONPath-compatible query syntax in .ALW scripts, CoSort users can analyze job performance and resource-control settings, while FieldShield and other SortCL users can audit sensitive-data<\/p>\n<div><a class=\"btn-filled btn\" href=\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\" title=\"Wrangling IRI Logs for Speed &#038; Security Insights\">Read More<\/a><\/div>\n","protected":false},"author":229,"featured_media":19297,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[34],"tags":[2485,2478,1297,2483,15,2479,2476,2484,2470,2486,2480,2481,2482,1336,68],"class_list":["post-19273","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-alw-scripts","tag-audit-log-wrangler","tag-audit-logs","tag-compliance-auditing","tag-data-security","tag-iri-audit-log-wrangler","tag-iri-ogs","tag-jpath","tag-log-analysis","tag-operational-governance","tag-ops-governance-system","tag-performance-tuning","tag-security-auditing","tag-siem","tag-sortcl"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.4 (Yoast SEO v23.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>IRI Audit Log Wrangler for Performance &amp; Security<\/title>\n<meta name=\"description\" content=\"Learn how IRI Audit Log Wrangler queries OGS audit logs to analyze SortCL performance, audit sensitive data activity, and support compliance reviews.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wrangling IRI Logs for Speed &amp; Security Insights\" \/>\n<meta property=\"og:description\" content=\"Learn how IRI Audit Log Wrangler queries OGS audit logs to analyze SortCL performance, audit sensitive data activity, and support compliance reviews.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\" \/>\n<meta property=\"og:site_name\" content=\"IRI\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T19:44:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1110\" \/>\n\t<meta property=\"og:image:height\" content=\"532\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jorge Canales\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jorge Canales\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\"},\"author\":{\"name\":\"Jorge Canales\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/person\/9e5a911b11ccc0d62e0ada86208c6aa6\"},\"headline\":\"Wrangling IRI Logs for Speed &#038; Security Insights\",\"datePublished\":\"2026-09-09T19:44:59+00:00\",\"dateModified\":\"2026-09-09T19:44:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\"},\"wordCount\":2366,\"publisher\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png\",\"keywords\":[\"ALW Scripts\",\"Audit Log Wrangler\",\"audit logs\",\"Compliance Auditing\",\"data security\",\"IRI Audit Log Wrangler\",\"IRI OGS\",\"JPath\",\"Log Analysis\",\"Operational Governance\",\"Ops Governance System\",\"Performance Tuning\",\"Security Auditing\",\"SIEM\",\"SortCL\"],\"articleSection\":[\"IRI Business\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\",\"url\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\",\"name\":\"IRI Audit Log Wrangler for Performance & Security\",\"isPartOf\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png\",\"datePublished\":\"2026-09-09T19:44:59+00:00\",\"dateModified\":\"2026-09-09T19:44:59+00:00\",\"description\":\"Learn how IRI Audit Log Wrangler queries OGS audit logs to analyze SortCL performance, audit sensitive data activity, and support compliance reviews.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage\",\"url\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png\",\"contentUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png\",\"width\":1110,\"height\":532,\"caption\":\"Audit log analysis illustration showing performance metrics on the left, JSON log inspection and command-line querying in the center, and security and compliance review on the right.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.iri.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wrangling IRI Logs for Speed &#038; Security Insights\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.iri.com\/blog\/#website\",\"url\":\"https:\/\/www.iri.com\/blog\/\",\"name\":\"IRI\",\"description\":\"Total Data Management Blog\",\"publisher\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.iri.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.iri.com\/blog\/#organization\",\"name\":\"IRI\",\"url\":\"https:\/\/www.iri.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png\",\"contentUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png\",\"width\":750,\"height\":206,\"caption\":\"IRI\"},\"image\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/person\/9e5a911b11ccc0d62e0ada86208c6aa6\",\"name\":\"Jorge Canales\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6d3b0b7e8c24fd8545bc9df321d9a2a2?s=96&d=blank&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6d3b0b7e8c24fd8545bc9df321d9a2a2?s=96&d=blank&r=g\",\"caption\":\"Jorge Canales\"},\"url\":\"https:\/\/www.iri.com\/blog\/author\/jorgecarnales\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"IRI Audit Log Wrangler for Performance & Security","description":"Learn how IRI Audit Log Wrangler queries OGS audit logs to analyze SortCL performance, audit sensitive data activity, and support compliance reviews.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/","og_locale":"en_US","og_type":"article","og_title":"Wrangling IRI Logs for Speed & Security Insights","og_description":"Learn how IRI Audit Log Wrangler queries OGS audit logs to analyze SortCL performance, audit sensitive data activity, and support compliance reviews.","og_url":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/","og_site_name":"IRI","article_published_time":"2026-09-09T19:44:59+00:00","og_image":[{"width":1110,"height":532,"url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png","type":"image\/png"}],"author":"Jorge Canales","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jorge Canales","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#article","isPartOf":{"@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/"},"author":{"name":"Jorge Canales","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/person\/9e5a911b11ccc0d62e0ada86208c6aa6"},"headline":"Wrangling IRI Logs for Speed &#038; Security Insights","datePublished":"2026-09-09T19:44:59+00:00","dateModified":"2026-09-09T19:44:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/"},"wordCount":2366,"publisher":{"@id":"https:\/\/www.iri.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png","keywords":["ALW Scripts","Audit Log Wrangler","audit logs","Compliance Auditing","data security","IRI Audit Log Wrangler","IRI OGS","JPath","Log Analysis","Operational Governance","Ops Governance System","Performance Tuning","Security Auditing","SIEM","SortCL"],"articleSection":["IRI Business"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/","url":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/","name":"IRI Audit Log Wrangler for Performance & Security","isPartOf":{"@id":"https:\/\/www.iri.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage"},"image":{"@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png","datePublished":"2026-09-09T19:44:59+00:00","dateModified":"2026-09-09T19:44:59+00:00","description":"Learn how IRI Audit Log Wrangler queries OGS audit logs to analyze SortCL performance, audit sensitive data activity, and support compliance reviews.","breadcrumb":{"@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#primaryimage","url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png","contentUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png","width":1110,"height":532,"caption":"Audit log analysis illustration showing performance metrics on the left, JSON log inspection and command-line querying in the center, and security and compliance review on the right."},{"@type":"BreadcrumbList","@id":"https:\/\/www.iri.com\/blog\/iri\/business\/iri-audit-log-wrangler-performance-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.iri.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Wrangling IRI Logs for Speed &#038; Security Insights"}]},{"@type":"WebSite","@id":"https:\/\/www.iri.com\/blog\/#website","url":"https:\/\/www.iri.com\/blog\/","name":"IRI","description":"Total Data Management Blog","publisher":{"@id":"https:\/\/www.iri.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.iri.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.iri.com\/blog\/#organization","name":"IRI","url":"https:\/\/www.iri.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png","contentUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png","width":750,"height":206,"caption":"IRI"},"image":{"@id":"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/person\/9e5a911b11ccc0d62e0ada86208c6aa6","name":"Jorge Canales","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6d3b0b7e8c24fd8545bc9df321d9a2a2?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6d3b0b7e8c24fd8545bc9df321d9a2a2?s=96&d=blank&r=g","caption":"Jorge Canales"},"url":"https:\/\/www.iri.com\/blog\/author\/jorgecarnales\/"}]}},"jetpack_featured_media_url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2026\/09\/featured-image-Wrangling-IRI-Logs-for-Speed-Security-Insights.png","_links":{"self":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts\/19273"}],"collection":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/users\/229"}],"replies":[{"embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/comments?post=19273"}],"version-history":[{"count":14,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts\/19273\/revisions"}],"predecessor-version":[{"id":19298,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts\/19273\/revisions\/19298"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/media\/19297"}],"wp:attachment":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/media?parent=19273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/categories?post=19273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/tags?post=19273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}