# Audit logging in Elastic Cloud

**URL:** <https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688>\
**Category:** Kibana\
**Created:** [December 6, 2023, 1:20am UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688 "2023-12-06T01:20:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lreger](https://avatars.discourse-cdn.com/v4/letter/l/ecae2f/32.png) [@lreger](https://discuss.elastic.co/u/lreger)\
**Post date:** [December 6, 2023, 1:20am UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688/1 "2023-12-06T01:20:12Z")

</div>

I have two questions I was hoping someone could answer.

Question 1: I am using an elastic cloud deployment running ES 7.17.5. I know how to enable audit logging and ship those logs to my monitoring deployment. I noticed however that this does not use the fully ECS compatible fields. If I was on a standalone cluster I would add an xpack.security.audit.appender to the config, but cloud does not seem to allow this option. How can I enable this in cloud?

Question 2: I have two wholly separate cloud instances, one for monitoring and one that is the production environment. These are NOT under the same cloud account. I would like to ship the production environment clusters logs and metrics to my monitoring environment. Is this possible?

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [December 27, 2023, 10:21pm UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688/2 "2023-12-27T22:21:03Z")

</div>

@Larry_Gregory could we please get some help here?

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688/3 "2024-01-03T17:08:34Z")

</div>

@lreger For Question 1, it's not the most straightforward, but the [docs](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-manage-kibana-settings.html#ece_logging_and_audit_settings) mention:

> `xpack.security.audit.appender.type`  
> When set to _"rolling-file"_ and `xpack.security.audit.enabled` is set to _true_, Kibana ECS audit logs are enabled. Beginning with version 8.0, this setting is no longer necessary for ECS audit log output; it’s only necessary to set `xpack.security.audit.enabled` to `true`

You stated:

> If I was on a standalone cluster I would add an xpack.security.audit.appender to the config, but cloud does not seem to allow this option. How can I enable this in cloud?

Did you get an error message when attempting to configure `xpack.security.audit.appender.type`?

For Question 2: I don't believe this is supported at this time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2024, 5:09pm UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688/4 "2024-01-31T17:09:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
