# Audit Logging for Elastic Search 2.3.1 with Shield plugin

**URL:** <https://discuss.elastic.co/t/audit-logging-for-elastic-search-2-3-1-with-shield-plugin/56737>\
**Category:** Elasticsearch\
**Created:** [July 29, 2016, 2:16pm UTC](https://discuss.elastic.co/t/audit-logging-for-elastic-search-2-3-1-with-shield-plugin/56737 "2016-07-29T14:16:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![habuivan](https://avatars.discourse-cdn.com/v4/letter/h/8c91f0/32.png) [@habuivan](https://discuss.elastic.co/u/habuivan)\
**Post date:** [July 29, 2016, 2:16pm UTC](https://discuss.elastic.co/t/audit-logging-for-elastic-search-2-3-1-with-shield-plugin/56737/1 "2016-07-29T14:16:41Z")

</div>

Hi guys,

We have a project from a client and the requirement is to setup audit logs for all the activities in Kibana/ES. We setup Shield trial and it worked nicely. However one of the requirement is to capture what data fields/time frame that the queries ran. For ex, we want to see the activity of user A after they logged in, what queries/dashboards they accessed within what time range against what columns.

I checked the documentation but the log level for Shield doesn't specify anything like that. Can you guys please advise?

Also, anyway to achieve such things without using Shield?

Thank you,  
Ha

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [July 29, 2016, 3:00pm UTC](https://discuss.elastic.co/t/audit-logging-for-elastic-search-2-3-1-with-shield-plugin/56737/2 "2016-07-29T15:00:00Z")

</div>

Unfortunately, that's not currently possible with Shield. Shield can log the endpoints a user accesses (via the `access_granted` log), but it currently doesn't log the request body. So you won't know what queries/times/dates they are running.

It's something we'd like to add to audit logging, just not sure when it'll be added 🙂

Without Shield, you'd need to setup some kind of proxy that intercepts the requests, logs the endpoint + body, then forwards it to Kibana. You'd also have to setup the ACL etc so that users can authorize and only access their allowed resources, and some way to collect those logs to send somewhere for processing.

---

<div class="post-metadata">

**Author:** ![habuivan](https://avatars.discourse-cdn.com/v4/letter/h/8c91f0/32.png) [@habuivan](https://discuss.elastic.co/u/habuivan)\
**Post date:** [July 29, 2016, 4:52pm UTC](https://discuss.elastic.co/t/audit-logging-for-elastic-search-2-3-1-with-shield-plugin/56737/3 "2016-07-29T16:52:56Z")

</div>

thanks for the prompt reply Zachary. We will dig into further and see if anything we can do anything by setting up the interception.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:31pm UTC](https://discuss.elastic.co/t/audit-logging-for-elastic-search-2-3-1-with-shield-plugin/56737/4 "2017-07-05T22:31:41Z")

</div>


