# Audit Logging Issue

**URL:** <https://discuss.elastic.co/t/audit-logging-issue/91876>\
**Category:** Elasticsearch\
**Created:** [July 5, 2017, 10:18am UTC](https://discuss.elastic.co/t/audit-logging-issue/91876 "2017-07-05T10:18:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiranilla](https://avatars.discourse-cdn.com/v4/letter/k/8e7dd6/32.png) [@kiranilla](https://discuss.elastic.co/u/kiranilla)\
**Post date:** [July 5, 2017, 10:18am UTC](https://discuss.elastic.co/t/audit-logging-issue/91876/1 "2017-07-05T10:18:54Z")

</div>

Hi,

I made an entry in the elasticsearch.yml file :  
`xpack.security.audit.enabled: true`

After this i am able to see the logs in the `elasticsearch_access.log`

Again i edited the elasticsearch.yml file and made the following entry to log the index to a particular log file:  
`xpack.security.audit.enabled: true`  
`xpack.security.audit.outputs: [aircel-db, airceldblogger_access.log]`

Now the Elasticsearch itself is not starting, it is crashing with the following error:

```
2017-07-05T15:38:37,233][ERROR][o.e.b.ElasticsearchUncaughtExceptionHandler] [] fatal error in thread [main], exiting
java.lang.Error: security initialization failed
        at org.elasticsearch.xpack.XPackPlugin.createComponents(XPackPlugin.java:266) ~[?:?]
        at org.elasticsearch.node.Node.lambda$new$7(Node.java:410) ~[elasticsearch-5.4.0.jar:5.4.0]
        at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:267) ~[?:1.8.0_121]
        at java.util.ArrayList$ArrayListSpliterator.forEachRemaining(ArrayList.java:1374) ~[?:1.8.0_121]
        at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:481) ~[?:1.8.0_121]
        at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:471) ~[?:1.8.0_121]
        at java.util.stream.ReduceOps$ReduceOp.evaluateSequential(ReduceOps.java:708) ~[?:1.8.0_121]
        at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234) ~[?:1.8.0_121]
        at java.util.stream.ReferencePipeline.collect(ReferencePipeline.java:499) ~[?:1.8.0_121]
        at org.elasticsearch.node.Node.<init>(Node.java:412) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.node.Node.<init>(Node.java:242) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.bootstrap.Bootstrap$6.<init>(Bootstrap.java:242) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:242) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:360) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:123) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:114) ~[elasticsearch-5.4.0.jar:5.4.0]
        at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:67) ~[elasticsearch-5.4.0.jar:5.4.0]

```

Please help me in resolving this issue..... Thanks in advance..

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 5, 2017, 1:02pm UTC](https://discuss.elastic.co/t/audit-logging-issue/91876/2 "2017-07-05T13:02:36Z")

</div>

> [@](#):
>
> ```
> xpack.security.audit.outputs: [aircel-db, airceldblogger_access.log]
> 
> ```

Those are not valid options for the audit outputs setting.

From [the documentation](https://www.elastic.co/guide/en/x-pack/5.4/auditing.html)

```auto
xpack.security.audit.outputs: [index, logfile]

```

The allowable values are _literally_ `index` and `logfile`.  
You cannot specify an index name or file name in that setting, you just specify whether you want to output your audit records to an _index_, a _logfile_, or both.

---

<div class="post-metadata">

**Author:** ![kiranilla](https://avatars.discourse-cdn.com/v4/letter/k/8e7dd6/32.png) [@kiranilla](https://discuss.elastic.co/u/kiranilla)\
**Post date:** [July 7, 2017, 6:56am UTC](https://discuss.elastic.co/t/audit-logging-issue/91876/3 "2017-07-07T06:56:29Z")

</div>

**Thanks Tim....** for confirming.  
But how should i log for a particular index in a particular log file?

Eg:

> xpack.security.audit.outputs: [aircel-db, airceldblogger\_access.log]

I want to log "aricel-db" index to a "airceldblogger\_access.log" log file.

Could you please suggest me on this.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 7, 2017, 7:03am UTC](https://discuss.elastic.co/t/audit-logging-issue/91876/4 "2017-07-07T07:03:44Z")

</div>

> [@kiranilla](#):
>
> I want to log "aricel-db" index to a "airceldblogger\_access.log" log file.

It is not possible to explicitly configure X-Pack to audit to different locations based on the index - many of the audit records are _not_ index specific.

If you want to write **all** audit records to a specific file then [from the documentation](https://www.elastic.co/guide/en/x-pack/5.4/auditing.html):

> [@](#):
>
> You configure also configure how the logfile is written in the log4j2.properties file located in CONFIG\_DIR/x-pack.

---

<div class="post-metadata">

**Author:** ![kiranilla](https://avatars.discourse-cdn.com/v4/letter/k/8e7dd6/32.png) [@kiranilla](https://discuss.elastic.co/u/kiranilla)\
**Post date:** [July 18, 2017, 9:32am UTC](https://discuss.elastic.co/t/audit-logging-issue/91876/5 "2017-07-18T09:32:07Z")

</div>

**Thanks Tim for reply and suggestion.**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2017, 9:32am UTC](https://discuss.elastic.co/t/audit-logging-issue/91876/6 "2017-08-15T09:32:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
