Apache log4j logo Apache logging services logo

Download Apache Log4j Audit

Apache Log4j Audit is distributed under the Apache License, version 2.0.

The link in the Mirrors column should display a list of available mirrors with a default selection based on your inferred location. If you do not see that page, try a different browser. The checksum and signature are links to the originals on the main distribution server.

Distribution Mirrors Checksum Signature
Apache Log4j Audit binary (tar.gz) apache-log4j-audit-1.0.1-bin.tar.gz apache-log4j-audit-1.0.1-bin.tar.gz.sha512 apache-log4j-audit-1.0.1-bin.tar.gz.asc
Apache Log4j Audit binary (zip) apache-log4j-audit-1.0.1-bin.zip apache-log4j-audit-1.0.1-bin.zip.sha512 apache-log4j-audit-1.0.1-bin.zip.asc
Apache Log4j Audit source (tar.gz) apache-log4j-audit-1.0.1-src.tar.gz apache-log4j-audit-1.0.1-src.tar.gz.sha512 apache-log4j-audit-1.0.1-src.tar.gz.asc
Apache Log4j Audit source (zip) apache-log4j-audit-1.0.1-src.zip apache-log4j-audit-1.0.1-src.zip.sha512 apache-log4j-audit-1.0.1-src.zip.asc

It is essential that you verify the integrity of the downloaded files using the PGP or SHA signatures. Please read Verifying Apache HTTP Server Releases for more information on why you should verify our releases.

The PGP signatures can be verified using PGP or GPG. First download the KEYS as well as the asc signature file for the relevant distribution. Make sure you get these files from the main distribution directory, rather than from a mirror. Then verify the signatures using

gpg --import KEYS
gpg --verify apache-log4j-audit-1.0.1-bin.tar.gz.asc

Apache Log4j 1.0.1 is signed by Ralph Goers (B3D8E1BA)

Alternatively, you can verify the MD5 signature on the files. A unix program called sha512sum or gpg is included in many unix distributions.

All previous releases of Apache log4j-Audit can be found in the archive repository.