# Audit log file does not appear in the node

**URL:** <https://discuss.elastic.co/t/audit-log-file-does-not-appear-in-the-node/246684>\
**Category:** Elasticsearch\
**Created:** [August 27, 2020, 8:29pm UTC](https://discuss.elastic.co/t/audit-log-file-does-not-appear-in-the-node/246684 "2020-08-27T20:29:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kasscharal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kasscharal/32/20001_2.png) [@kasscharal](https://discuss.elastic.co/u/kasscharal)\
**Post date:** [August 27, 2020, 8:29pm UTC](https://discuss.elastic.co/t/audit-log-file-does-not-appear-in-the-node/246684/1 "2020-08-27T20:29:16Z")

</div>

In my Elasticsearch cluster (version 7.6.2 - installed using the [elasticsearch.k8s.elastic.co/v1](http://elasticsearch.k8s.elastic.co/v1) resource) I have set `xpack.security.audit.enabled` to `true` under my `nodeSets`:

```auto
GET /_xpack/usage
...
    "audit" : {
      "outputs" : [
        "logfile"
      ],
      "enabled" : true
    },
...

```

but no `<clustername>_audit.json` is created under `ES_HOME/logs`.

However in my `ES_HOME/config/log4j2.properties` file I see:

```auto
logger.xpack_security_audit_logfile.name = org.elasticsearch.xpack.security.audit.logfile.LoggingAuditTrail
logger.xpack_security_audit_logfile.level = info
logger.xpack_security_audit_logfile.appenderRef.audit_rolling.ref = audit_rolling
logger.xpack_security_audit_logfile.additivity = false
appender.audit_rolling.type = Console
appender.audit_rolling.name = audit_rolling

```

Is the `audit_rolling.type` correct? Do I need any extra configuration?  
Thank you.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 31, 2020, 3:43am UTC](https://discuss.elastic.co/t/audit-log-file-does-not-appear-in-the-node/246684/2 "2020-08-31T03:43:11Z")

</div>

Audit logging is a [Gold license](https://www.elastic.co/subscriptions) and above feature, so make sure you have the correct license level.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2020, 3:43am UTC](https://discuss.elastic.co/t/audit-log-file-does-not-appear-in-the-node/246684/3 "2020-09-28T03:43:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
