# Configure audit logging

**URL:** <https://discuss.elastic.co/t/configure-audit-logging/375772>\
**Category:** Elasticsearch\
**Created:** [March 12, 2025, 10:49am UTC](https://discuss.elastic.co/t/configure-audit-logging/375772 "2025-03-12T10:49:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![danil.kalmikov1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danil.kalmikov1/32/134086_2.png) [@danil.kalmikov1](https://discuss.elastic.co/u/danil.kalmikov1)\
**Post date:** [March 12, 2025, 10:49am UTC](https://discuss.elastic.co/t/configure-audit-logging/375772/1 "2025-03-12T10:49:53Z")

</div>

Hello, Community.

I want to collect audit logs connected to user activity (like user create/delete, set/change password, create new role, delete role, change role, change user role, success/failed auth etc.) Is it possible to log all these actions?  
For example, I found auth logs in elasticsearch.log. But get user creation/deletion events was difficult. For this, I prescribed the following construction in kibana.yml:  
logging:  
appenders:  
audit\_file:  
type: file  
fileName: /var/log/kibana/audit.log  
layout:  
type: json  
loggers:  
- name: plugins.security.audit  
level: debug  
appenders: [audit\_file]  
- name: plugins.security  
level: debug  
appenders: [audit\_file]  
- name: http.server.response  
level: debug  
appenders: [audit\_file]  
And only on level debug of http.server.response category i found this logs. So, are there any easier way to get this events? Has anyone encountered such a case?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 12, 2025, 1:21pm UTC](https://discuss.elastic.co/t/configure-audit-logging/375772/2 "2025-03-12T13:21:17Z")

</div>

> [@danil.kalmikov1](#):
>
> I want to collect audit logs connected to user activity (like user create/delete, set/change password, create new role, delete role, change role, change user role, success/failed auth etc.) Is it possible to log all these actions?

It is possible if you have a paid license like platinum or enterprise, with the basic license it is not possible.

The documentation for enabling audit is [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html), did you check it already?
