# Audit Log Exclude by Origin / Principal

**URL:** <https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902>\
**Category:** Elasticsearch\
**Created:** [January 24, 2018, 5:10pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902 "2018-01-24T17:10:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![lask001](https://avatars.discourse-cdn.com/v4/letter/l/4da419/32.png) [@lask001](https://discuss.elastic.co/u/lask001)\
**Post date:** [January 24, 2018, 5:10pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/1 "2018-01-24T17:10:16Z")

</div>

I'm setting up audit log configurations, and I'm wondering if it's possible to not log events based on the contents. Here's an example of a log I'm trying to prevent:

`[2018-01-24T10:42:37,950] [transport] [access_granted] origin_type=[rest], origin_address=[127.0.0.1], principal=[elastic], action=[indices:admin/template/put], indices=[.monitoring-logstash-2*], request=[PutIndexTemplateRequest]`

I don't want the logs to record when the principal is `elastic`, or the origin\_address is `127.0.0.1`. Is it possible to configure the audit logs this way, or does anyone have a clever work around?

---

<div class="post-metadata">

**Author:** ![jeje232](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeje232/32/27564_2.png) [@jeje232](https://discuss.elastic.co/u/jeje232)\
**Post date:** [January 24, 2018, 7:26pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/2 "2018-01-24T19:26:49Z")

</div>

**I have a same problem, trying to apply filter in my logs but I don't now why elasticsearch run without using configuration.**  
**in my elastic configuration I active:**  
**xpack.security.enabled: true**  
**xpack.security.audit.enabled: true**  
**xpack.security.audit.outputs: [index, logfile]**  
**xpack.security.audit.logfile.events.emit\_request\_body: true**  
**--------------------------------------------------------------------------------------------**

**and in my I trying lot of stuff and nothing change in my logs**  
**x-pack/log4j2.properties:**  
**--------------------------------------------------------------------------------------------**  
**# MY RULES**  
**appender.audit\_rolling.filter.regex.type = RegexFilter**  
**appender.audit\_rolling.filter.regex.onMatch = DENY**  
**#appender.audit\_rolling.filter.regex.regex = .principal=.\_xpack\_security.**  
**appender.audit\_rolling.filter.regex.regex = .principal=[\_xpack\_security].**  
**appender.audit\_rolling.filter.regex.onMisMatch = ACCEPT**  
**--------------------------------------------------------------------------------------------**

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 24, 2018, 9:08pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/3 "2018-01-24T21:08:06Z")

</div>

> [@jeje232](#):
>
> .principal=[\_xpack\_security]

That Regular Expression doesn't match what you're expecting it to.  
`[` and `]` have special meaning in a regular expression - you'll need to escape them in the properties file.

---

<div class="post-metadata">

**Author:** ![lask001](https://avatars.discourse-cdn.com/v4/letter/l/4da419/32.png) [@lask001](https://discuss.elastic.co/u/lask001)\
**Post date:** [January 25, 2018, 2:00am UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/4 "2018-01-25T02:00:36Z")

</div>

I found this thread: [Kibana automatic activity is flooding audit log](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413/10)

I haven't been able to get any of the combinations in that thread to work for me. I've tried things like:

`.*elastic*.*`, `.*principal=.elastic.,.*`, `.principal=\[elastic\].`, `.principal=\\[elastic\\].`, `.*principal=\[elastic\].*`

Any suggestions, or do you see what I'm missing?

---

<div class="post-metadata">

**Author:** ![jeje232](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeje232/32/27564_2.png) [@jeje232](https://discuss.elastic.co/u/jeje232)\
**Post date:** [January 25, 2018, 7:28am UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/5 "2018-01-25T07:28:29Z")

</div>

Thank you TimV for your reply,

(\ desapeared when I saved my comment I need to put \\ and \* !)

Yes it's true, in reality the correct line I put was:  
appender.audit\_rolling.filter.regex.regex = .principal=\[\_xpack\_security\].  
This would be remove all the line in the log file with " principal=[\_xpack\_security]" expresion

I tried to last week:  
#appender.audit\_rolling.filter.regex.regex = .\*principal=.kibana...action=.cluster:monitor.\*|.\*action=.cluster:admin.\*|.\*indices=..kibana.,.\*|.\*indices=..\*.,.\*

Didn't work to.

I don't now whats wrong with my filters or config...

---

<div class="post-metadata">

**Author:** ![lask001](https://avatars.discourse-cdn.com/v4/letter/l/4da419/32.png) [@lask001](https://discuss.elastic.co/u/lask001)\
**Post date:** [January 25, 2018, 4:51pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/6 "2018-01-25T16:51:28Z")

</div>

With a log of trial and error I think I've gotten it figured out. I could have sword I tried this combination last night, but it seems to be working now so I must have messed something up if I did:

```
appender.audit_rolling.filter.regex.type = RegexFilter
appender.audit_rolling.filter.regex.onMatch = DENY
appender.audit_rolling.filter.regex.regex = .*principal=.elastic.*|.*principal=._xpack_security.*
appender.audit_rolling.filter.regex.onMisMatch = ACCEPT

```

This works for me on elastic 5.6.1. I found that if you include a space between around the `|` it will cause the patterns to not match correctly, which is probably what I was messing up.

---

<div class="post-metadata">

**Author:** ![jeje232](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeje232/32/27564_2.png) [@jeje232](https://discuss.elastic.co/u/jeje232)\
**Post date:** [January 25, 2018, 5:13pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/7 "2018-01-25T17:13:39Z")

</div>

I will trying right now!

---

<div class="post-metadata">

**Author:** ![jeje232](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeje232/32/27564_2.png) [@jeje232](https://discuss.elastic.co/u/jeje232)\
**Post date:** [January 25, 2018, 6:21pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/8 "2018-01-25T18:21:39Z")

</div>

Nice!!

Work perfectly.  
Good work Colin for find the error in the expression!!!  
(y) (y) (y)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2018, 6:22pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/9 "2018-02-22T18:22:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
