I am wondering if audit logging like described here (https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html) is also available for elastic cloud on kubernetes deployments. If so I am wondering about where the _audit.json file is being stored, if it is protected against deletion and if it also logs events like for example index deletion?
I am trying to ensure that in case that someone unauthorized gets access to the cluster and for example tries to delete his traces we do have logs that show it.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.