# Ambiguous documentation for audit logs

**URL:** <https://discuss.elastic.co/t/ambiguous-documentation-for-audit-logs/304505>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 11, 2022, 9:14pm UTC](https://discuss.elastic.co/t/ambiguous-documentation-for-audit-logs/304505 "2022-05-11T21:14:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmendez92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cmendez92/32/78173_2.png) [@cmendez92](https://discuss.elastic.co/u/cmendez92)\
**Post date:** [May 11, 2022, 9:14pm UTC](https://discuss.elastic.co/t/ambiguous-documentation-for-audit-logs/304505/1 "2022-05-11T21:14:20Z")

</div>

Elasticsearch documentation is ambiguous in audit logs section. Literally says:

> If configured, auditing settings must be set on every node in the cluster.

Is that correct? I think with only 1 node we can get all audit logs, the I have a few questions:

1. Is any node with any role valid to extract the audit events?

2. The management of the audit event logs that comes by default does not have any type of deletion or storage in Log4j. Is this normal? In principle, it must have a normal retention so that it does not cause any problem.

3. Is it possible to update the documentation and change the default behavior of elasticsearch regarding these logs? If it is possible, how can you make a request to update the elastic code?

Greetings and thank you very much in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2022, 9:14pm UTC](https://discuss.elastic.co/t/ambiguous-documentation-for-audit-logs/304505/2 "2022-06-08T21:14:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
