# Audit logs or other way to ensure integrity of the logs

**URL:** <https://discuss.elastic.co/t/audit-logs-or-other-way-to-ensure-integrity-of-the-logs/247332>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [September 3, 2020, 6:35am UTC](https://discuss.elastic.co/t/audit-logs-or-other-way-to-ensure-integrity-of-the-logs/247332 "2020-09-03T06:35:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raulgs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raulgs/32/68308_2.png) [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Post date:** [September 3, 2020, 6:35am UTC](https://discuss.elastic.co/t/audit-logs-or-other-way-to-ensure-integrity-of-the-logs/247332/1 "2020-09-03T06:35:46Z")

</div>

Hi all,

I am wondering if audit logging like described here ([https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html)) is also available for elastic cloud on kubernetes deployments. If so I am wondering about where the `_audit.json` file is being stored, if it is protected against deletion and if it also logs events like for example index deletion?

I am trying to ensure that in case that someone unauthorized gets access to the cluster and for example tries to delete his traces we do have logs that show it.

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [September 3, 2020, 7:18am UTC](https://discuss.elastic.co/t/audit-logs-or-other-way-to-ensure-integrity-of-the-logs/247332/2 "2020-09-03T07:18:47Z")

</div>

You can set `xpack.security.audit.enabled : true` in the `config` section of the Elasticsearch resource.

All [audit logs end up in stdout by default](https://github.com/elastic/elasticsearch/pull/42671).

One way to grab those is to [setup filebeat](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat.html) so all logs from the Elasticsearch Pods are sent to a single logging cluster.

---

<div class="post-metadata">

**Author:** ![raulgs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raulgs/32/68308_2.png) [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Post date:** [September 3, 2020, 8:34am UTC](https://discuss.elastic.co/t/audit-logs-or-other-way-to-ensure-integrity-of-the-logs/247332/3 "2020-09-03T08:34:29Z")

</div>

Awesome thanks for you fast response 🙂  
Filebeats detects the audit logs and they can be filtered with `fileset.name: audit`

Is there also a way to protect the specific index from being deleted?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:12am UTC](https://discuss.elastic.co/t/audit-logs-or-other-way-to-ensure-integrity-of-the-logs/247332/4 "2022-11-04T08:12:21Z")

</div>


