# Details related to the index

**URL:** <https://discuss.elastic.co/t/details-related-to-the-index/195879>\
**Category:** Elasticsearch\
**Created:** [August 20, 2019, 9:50am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879 "2019-08-20T09:50:45Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![SukeshGupta](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@SukeshGupta](https://discuss.elastic.co/u/SukeshGupta)\
**Post date:** [August 20, 2019, 9:50am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/1 "2019-08-20T09:50:45Z")

</div>

Hi,

I have created many users and i want details regarding which user has updated/created the index.  
How to find out all the actions performed on the index by the user ?

We need to any changes in elastic yml file ?

Requesting anyone to please help me on this. Thanks!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 20, 2019, 10:18am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/2 "2019-08-20T10:18:48Z")

</div>

You can use [https://www.elastic.co/guide/en/elasticsearch/reference/current/auditing-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/auditing-settings.html). I think it requires a trial or gold license (commercial).

---

<div class="post-metadata">

**Author:** ![SukeshGupta](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@SukeshGupta](https://discuss.elastic.co/u/SukeshGupta)\
**Post date:** [August 20, 2019, 11:03am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/3 "2019-08-20T11:03:05Z")

</div>

Thanks for your reply @dadoonet.

I am using trial version and i have already enabled that in my yml file. But it will show only related to these things - `access_denied, access_granted, anonymous_access_denied, authentication_failed, connection_denied, tampered_request, run_as_denied, run_as_granted`.

The logs will be like below :

`{"@timestamp":"2019-08-19T09:53:10,029", "node.id":"wnSs8X2oRmmmd0LMaj3HBA", "event.type":"rest", "event.action":"anonymous_access_denied", "origin.type":"rest", "origin.address":"127.0.0.1:54520", "url.path":"/", "request.method":"GET", "request.id":"21aOudd2RC-3cTyTelPKQA"}`

But it will not show which user has updated/created index, at what the index has been updated. All these things it will not show.

Can you please tell me is there any other way. Thanks!

---

<div class="post-metadata">

**Author:** ![SukeshGupta](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@SukeshGupta](https://discuss.elastic.co/u/SukeshGupta)\
**Post date:** [August 22, 2019, 4:51am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/4 "2019-08-22T04:51:25Z")

</div>

Hi,

Can anyone please provide the solution for this topic.  
Thanks!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 22, 2019, 8:33am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/5 "2019-08-22T08:33:25Z")

</div>

I don't really know but I guess you can see some messages like:

```auto
{ ..., "url.path":"/foo", "request.method":"PUT"}
{ ..., "url.path":"/foo", "request.method":"DELETE"}

```

Can't you?

---

<div class="post-metadata">

**Author:** ![SukeshGupta](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@SukeshGupta](https://discuss.elastic.co/u/SukeshGupta)\
**Post date:** [August 22, 2019, 1:01pm UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/6 "2019-08-22T13:01:37Z")

</div>

Now Im able get those things. But whats happening is its generating many logs for fraction of seconds.

How to limit these logs to particular indices only ?

I have added the below line in my YML file :

xpack.monitoring.collection.indices: employee

But its not working. Its generating many logs for fraction of seconds. Please help on this @dadoonet. Thanks for your response @dadoonet.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 22, 2019, 6:18pm UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/7 "2019-08-22T18:18:34Z")

</div>

I don't know. Leaving the question to someone else.

---

<div class="post-metadata">

**Author:** ![SukeshGupta](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@SukeshGupta](https://discuss.elastic.co/u/SukeshGupta)\
**Post date:** [August 23, 2019, 5:17am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/8 "2019-08-23T05:17:23Z")

</div>

Okay thanks @dadoonet. Anyone please help me on this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2019, 5:18am UTC](https://discuss.elastic.co/t/details-related-to-the-index/195879/9 "2019-09-20T05:18:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
