# Detailed user audit logs for Kibana Dev tools

**URL:** <https://discuss.elastic.co/t/detailed-user-audit-logs-for-kibana-dev-tools/219340>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-security\
**Created:** [February 14, 2020, 9:45am UTC](https://discuss.elastic.co/t/detailed-user-audit-logs-for-kibana-dev-tools/219340 "2020-02-14T09:45:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![soumendra](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@soumendra](https://discuss.elastic.co/u/soumendra)\
**Post date:** [February 14, 2020, 9:45am UTC](https://discuss.elastic.co/t/detailed-user-audit-logs-for-kibana-dev-tools/219340/1 "2020-02-14T09:45:42Z")

</div>

ES version: 7.3.2  
X-pack: Platinum

We have OpenID based user authentication in Elasticsearch.  
We need to check the activity done by users after they sign-in, especially the activity which involves running queries on Dev tools in Kibana.

The current audit logs do not show these details which we configured with the following configuration:

```auto
xpack.security.audit.enabled: true
xpack.security.audit.logfile.events.emit_request_body: true

```

We are getting logs like below with not granular level of details as required.

```auto
{"@timestamp":"2020-02-14T01:35:46,471", "node.id":"Hw0yZ8sgR7wiTNI3tDt5Gg", "event.type":"transport", "event.action":"access_granted", "user.name":"_xpack_security", "user.realm":"__attach", "user.roles":["superuser"], "origin.type":"local_node", "origin.address":"ip.address:9300", "request.id":"a0R5c5mZSI6M8cowuSAGDg", "action":"indices:data/read/scroll/clear", "request.name":"ClearScrollRequest"}
{"@timestamp":"2020-02-14T01:35:46,471", "node.id":"Hw0yZ8sgR7wiTNI3tDt5Gg", "event.type":"transport", "event.action":"access_granted", "user.name":"_xpack_security", "user.realm":"__attach", "user.roles":["superuser"], "origin.type":"local_node", "origin.address":"ip.address:9300", "request.id":"a0R5c5mZSI6M8cowuSAGDg", "action":"indices:data/read/search[free_context/scroll]", "request.name":"ScrollFreeContextRequest"}
{"@timestamp":"2020-02-14T01:35:56,475", "node.id":"Hw0yZ8sgR7wiTNI3tDt5Gg", "event.type":"transport", "event.action":"access_granted", "user.name":"_xpack_security", "user.realm":"__attach", "user.roles":["superuser"], "origin.type":"local_node", "origin.address":"ip.address:9300", "request.id":"H-fdWUC1Snidy7vPtA2oGA", "action":"indices:data/read/msearch", "request.name":"MultiSearchRequest"}

```

Is there any way we can get user email-id or user name at least under these logs? Is this a limitation from Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [February 14, 2020, 10:45am UTC](https://discuss.elastic.co/t/detailed-user-audit-logs-for-kibana-dev-tools/219340/2 "2020-02-14T10:45:32Z")

</div>

Hi @soumendra,

Audit entries attributed to the `user.name`, which is running queries on Dev tools in Kibana, **should be present** in the audit log, among others. The entries that you've pasted above are generated by an internal system user of Elasticsearch (the `_xpack_security` username).

You might also be interested in the [Kibana audit logs](https://www.elastic.co/guide/en/kibana/current/xpack-security-audit-logging.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2020, 10:45am UTC](https://discuss.elastic.co/t/detailed-user-audit-logs-for-kibana-dev-tools/219340/3 "2020-03-13T10:45:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
