# Audit authentication failed

**URL:** <https://discuss.elastic.co/t/audit-authentication-failed/216467>\
**Category:** Elasticsearch\
**Created:** [January 24, 2020, 4:05pm UTC](https://discuss.elastic.co/t/audit-authentication-failed/216467 "2020-01-24T16:05:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ludovic9](https://avatars.discourse-cdn.com/v4/letter/l/977dab/32.png) [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Post date:** [January 24, 2020, 4:05pm UTC](https://discuss.elastic.co/t/audit-authentication-failed/216467/1 "2020-01-24T16:05:23Z")

</div>

Hi,  
I'm using elk stack in version 6.8.3, I have enabled security function, it's OK. Each beats needs an account to send logs to elasticsearch.

But I would like to track the authentication failed from agent and from Kibana.

I have this in elasticsearch.yml :

> xpack.security.audit.enabled: true  
> xpack.security.audit.outputs: ["logfile"]  
> xpack.security.audit.logfile.events.include: ["access\_denied", "authentication\_failed", "connection\_denied", "anonymous\_access\_denied", "run\_as\_denied"]

I have put this on each node.

and in kibana.yml I have this :

> logging.dest: "/var/log/kibana.log"  
> xpack.security.audit.enabled: true  
> server.ssl.enabled: true

I have restarted kibana and elasticsearch, I have configured winlogbeat with a wrong password, I don't see this server in my access.log or audit.log.

I see information in gc.log.0.current but it's not interesting.

What I have missed ?

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2020, 4:05pm UTC](https://discuss.elastic.co/t/audit-authentication-failed/216467/2 "2020-02-21T16:05:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
