# Destination of Audit Logs After Enabling Audit Logging on Kibana

**URL:** <https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 23, 2023, 11:39am UTC](https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846 "2023-11-23T11:39:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [November 23, 2023, 11:39am UTC](https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846/1 "2023-11-23T11:39:47Z")

</div>

Hi,

I am currently exploring the functionalities related to audit logging on Kibana and have a technical query regarding the destination of these logs once audit logging is enabled.

Specifically, upon enabling audit logging on Kibana, I would like to inquire whether the corresponding logs are directly routed to Kibana itself, or if it necessitates the use of intermediary tools such as Filebeat or similar solutions for their transmission.

Thank you in advance for your time and assistance.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 23, 2023, 12:16pm UTC](https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846/2 "2023-11-23T12:16:19Z")

</div>

> [@yago82](#):
>
> Specifically, upon enabling audit logging on Kibana, I would like to inquire whether the corresponding logs are directly routed to Kibana itself, or if it necessitates the use of intermediary tools such as Filebeat or similar solutions for their transmission.

If you do not have Filebeat or Elastic Agent consuming the Kibana logs, then you will need it, the log events are generated in the Kibana log file, if you want them in Elasticsearch you need to have filebeat or elastic agent reading the logs and shipping them to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2023, 12:16pm UTC](https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846/3 "2023-12-21T12:16:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
