# Detecting deletes

**URL:** <https://discuss.elastic.co/t/detecting-deletes/255570>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 16, 2020, 4:23pm UTC](https://discuss.elastic.co/t/detecting-deletes/255570 "2020-11-16T16:23:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 16, 2020, 4:23pm UTC](https://discuss.elastic.co/t/detecting-deletes/255570/1 "2020-11-16T16:23:11Z")

</div>

Hello,

I was hoping to find a way to detect deletion of documents in our Elasticsearch audit logs. But I cannot find any reference or event related to me testing deletion of docs with for example:

`DELETE av-002-2020.10/_doc/e6hh8HQBlvZ7gcHFnQNW`

I'd prefer not having to set:

`xpack.security.audit.logfile.events.emit_request_body: true`

As I tried that in the past and our PR cluster exploded..

So can someone confirm that there is no way to detect deletion of documents without setting `emit_request_body`?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 17, 2020, 1:13am UTC](https://discuss.elastic.co/t/detecting-deletes/255570/2 "2020-11-17T01:13:18Z")

</div>

What version of Elasticsearch?

Depending on how your auditing is setup you should be able to see something like (re-formated for clarity)

```auto
{
  "@timestamp": "2020-11-17T12:08:43,853",
  "node.name": "42Qe0Al",
  "node.id": "42Qe0AlWQl-yBE5hBTMkIg",
  "event.type": "transport",
  "event.action": "access_granted",
  "user.name": "elastic",
  "user.realm": "reserved",
  "user.roles": ["superuser"],
  "origin.type": "rest",
  "origin.address": "[::1]:57348",
  "request.id": "19QFv00PTx2iEySjELRgHA",
  "action": "indices:data/write/delete",
  "request.name": "DeleteRequest",
  "indices": ["index"]
}

```

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 17, 2020, 7:11am UTC](https://discuss.elastic.co/t/detecting-deletes/255570/3 "2020-11-17T07:11:21Z")

</div>

Thanks for your answer @TimV

> [@TimV](#):
>
> What version of Elasticsearch?

We are on 7.9.2 currently. We have a seperate monitoring cluster and Logstash node where our audit logs are indexed by a secondary Filebeat instance on each Elastic node. The audit logs are filtered in the Logstash node which drops events allowed done by system accounts. Thanks for confirming we should see "indices:data/write/delete". I'll have another look at some of the components to see why our deletes are not indexed.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 17, 2020, 7:29am UTC](https://discuss.elastic.co/t/detecting-deletes/255570/4 "2020-11-17T07:29:21Z")

</div>

@TimV Aha, I found a configuration error in some of our filebeat2.yml's, seems they are trying to index pr audit logs on qa nodes (probably copied from a pr to a qa node without changing the path).

After correcting the situation I was able to the find delete requests. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 7:29am UTC](https://discuss.elastic.co/t/detecting-deletes/255570/5 "2020-12-15T07:29:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
