# Best way to analyze secure document activity logs in Elasticsearch?

**URL:** <https://discuss.elastic.co/t/best-way-to-analyze-secure-document-activity-logs-in-elasticsearch/390834>\
**Category:** Elasticsearch\
**Created:** [October 5, 2026, 8:14am UTC](https://discuss.elastic.co/t/best-way-to-analyze-secure-document-activity-logs-in-elasticsearch/390834 "2026-10-05T08:14:44Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![George4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george4/32/148319_2.png) [@George4](https://discuss.elastic.co/u/George4)\
**Post date:** [October 5, 2026, 8:14am UTC](https://discuss.elastic.co/t/best-way-to-analyze-secure-document-activity-logs-in-elasticsearch/390834/1 "2026-10-05T08:14:44Z")

</div>

I’m exploring how to structure document activity data in Elasticsearch for a secure document-sharing / virtual data room workflow.

One of the platforms I’m looking at is SendNow.

The activity data includes document opens, viewer events, downloads, access attempts, timestamps, and engagement history.

For this kind of event-heavy data, is it better to store every activity as a separate Elasticsearch document, or group events by document or session?

Also, how would you normally handle mappings and retention for this type of audit/activity data?

Curious how others are handling similar workflows.
