# Audit log flexability

**URL:** <https://discuss.elastic.co/t/audit-log-flexability/115947>\
**Category:** Elasticsearch\
**Created:** [January 17, 2018, 9:39pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947 "2018-01-17T21:39:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)\
**Post date:** [January 17, 2018, 9:39pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947/1 "2018-01-17T21:39:34Z")

</div>

Hello All,  
Currently I'm using the audit log in x-pack but I have to suppress all of the access\_granted/authentication\_success events because they are way to noisy. Is there a way or a future plan for giving some flexibility around this? For instance can I just log authentication\_success for the ldap realm and not the native? I'm trying to get a dataset here that lets me know what users have logged in and don't need the millions of events for Filebeat, Kibana, ES and every other service that create over 4k of events per second.

```
  security:
    enabled: true
    audit:
      enabled: true
      outputs: [index]
      index:
        events:
          exclude: [access_granted, connection_granted, realm_authentication_failed]
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 17, 2018, 9:45pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947/2 "2018-01-17T21:45:52Z")

</div>

There are future plans to allow this, yes. Not sure of the ETA though.

---

<div class="post-metadata">

**Author:** ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)\
**Post date:** [January 17, 2018, 10:15pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947/3 "2018-01-17T22:15:01Z")

</div>

Ok, cool. Is there anything I could follow? I couldn't find a feature request or anything.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 17, 2018, 10:26pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947/4 "2018-01-17T22:26:11Z")

</div>

The X-Pack code and repo is not public sorry.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 17, 2018, 11:30pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947/5 "2018-01-17T23:30:30Z")

</div>

I'm afraid you'll have to just keep an eye on the release notes.

We're actively working on improvements to audit log filtering, so it should come out in an upcoming minor release (6.x.0, for some value of x).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2018, 11:31pm UTC](https://discuss.elastic.co/t/audit-log-flexability/115947/6 "2018-02-14T23:31:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
