Destination of Audit Logs After Enabling Audit Logging on Kibana


I am currently exploring the functionalities related to audit logging on Kibana and have a technical query regarding the destination of these logs once audit logging is enabled.

Specifically, upon enabling audit logging on Kibana, I would like to inquire whether the corresponding logs are directly routed to Kibana itself, or if it necessitates the use of intermediary tools such as Filebeat or similar solutions for their transmission.

Thank you in advance for your time and assistance.

If you do not have Filebeat or Elastic Agent consuming the Kibana logs, then you will need it, the log events are generated in the Kibana log file, if you want them in Elasticsearch you need to have filebeat or elastic agent reading the logs and shipping them to Elasticsearch.

