# Does Elasticsearch capture audit logs for Query DSL, EQL and SQL or Not?

**URL:** <https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398>\
**Category:** Elasticsearch\
**Created:** [July 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398 "2023-07-27T08:07:11Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Subrato1](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Post date:** [July 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/1 "2023-07-27T08:07:12Z")

</div>

Does Elasticsearch capture audit logs for Query DSL, EQL and SQL or Not???

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 8:59am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/2 "2023-07-27T08:59:02Z")

</div>

No. The list of events which could be captured by the audit logs is here: [Audit events | Elasticsearch Guide [8.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-event-types.html)

But you can use slow logs for this: [Slow Log | Elasticsearch Guide [8.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.9/index-modules-slowlog.html). I think that using `0` as the threshold will log everything. But be careful as it will be very verbose.

---

<div class="post-metadata">

**Author:** ![Subrato1](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Post date:** [July 27, 2023, 9:21am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/3 "2023-07-27T09:21:55Z")

</div>

I executed the POST query from REST API, and I am getting this Log (For WINDOWS) using Latest Version or Elasticsearch:

{"type":"audit", "timestamp":"2023-07-27T12:25:06,662+0530", "cluster.uuid":"PdxPNKJfRUOh-nJVi4R9jw", "node.name":"node-1", "node.id":"8vfClNdqTQKpxsWQ9jZFsQ", "host.name":"192.168.1.5", "host.ip":"192.168.1.5", "event.type":"rest", "event.action":"authentication\_success", "authentication.type":"REALM", "user.name":"elastic", "user.realm":"reserved", "origin.type":"rest", "origin.address":"[::1]:64848", "realm":"reserved", "url.path":"/ashish\_hcl/\_doc/1", "request.method":"POST", "request.body":" {\r\n "firstname": "Subhash",\r\n "lastname": "Chandra"\r\n}", "request.id":"qGhK\_WaNTiyI\_GwR1N8xQQ"}

But when I am using Elasticsearch 7.15.2 version in Red Hat Linux then I am not able to Get the audit logs.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 9:33am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/4 "2023-07-27T09:33:39Z")

</div>

How did you change the log level on the RedHat machine?

---

<div class="post-metadata">

**Author:** ![Subrato1](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Post date:** [July 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/5 "2023-07-27T09:36:02Z")

</div>

I did not change the log level by default it's INFO there. Configuration for both Windows and Red Hat machine is same only Difference is in Windows I am using latest version of Elasticsearch and in Red Hat I am using 7.15.2 version.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 9:48am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/6 "2023-07-27T09:48:39Z")

</div>

I don't know.  
I'd in any case upgrade the RedHat machine to benefit from all the security patches at least.

Did you activate the trial on the RedHat cluster?  
What are your elasticsearch.yml settings in the RedHat cluster?

And anyway, this is not related to the original question, right?

> Does Elasticsearch capture audit logs for Query DSL, EQL and SQL or Not???

The trace you shown:

```auto
{"type":"audit", "timestamp":"2023-07-27T12:25:06,662+0530", "cluster.uuid":"PdxPNKJfRUOh-nJVi4R9jw", "node.name":"node-1", "node.id":"8vfClNdqTQKpxsWQ9jZFsQ", "host.name":"192.168.1.5", "host.ip":"192.168.1.5", "event.type":"rest", "event.action":"authentication_success", "authentication.type":"REALM", "user.name":"elastic", "user.realm":"reserved", "origin.type":"rest", "origin.address":"[::1]:64848", "realm":"reserved", "url.path":"/ashish_hcl/_doc/1", "request.method":"POST", "request.body":" {\r\n "firstname": "Subhash",\r\n "lastname": "Chandra"\r\n}", "request.id":"qGhK_WaNTiyI_GwR1N8xQQ"}

```

Is an authentication one: `"event.action":"authentication_success"`. So not sure how this is all related and what you are trying to do.

---

<div class="post-metadata">

**Author:** ![Subrato1](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Post date:** [July 27, 2023, 10:05am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/7 "2023-07-27T10:05:20Z")

</div>

Yes, I activated the Trail License already.

Actually, I am executing queries DSL, EQL and SQL and I want audit logs for the queries which I perform.

Suppose I am using POST to create something in cluster:

POST demo/\_doc/2  
{  
"title":"Project2"  
}

And I am able to see the audit logs for this.

After this, I am executing this query:  
GET demo/\_search

But did not get audit log for above query.

My question is that Should we get SQL, EQL and Query DSL queries also or not?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 10:08am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/8 "2023-07-27T10:08:44Z")

</div>

> [@Subrato1](#):
>
> And I am able to see the audit logs for this.

Could you share the audit logs you got for this call?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 10:25am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/9 "2023-07-27T10:25:39Z")

</div>

@ashishshukla wrote:

Please find the below event log

```auto
{"type":"audit", "timestamp":"2023-07-27T15:40:31,728+0530", "cluster.uuid":"PdxPNKJfRUOh-nJVi4R9jw", "node.name":"node-1", "node.id":"8vfClNdqTQKpxsWQ9jZFsQ", "host.name":"192.168.251.17", "host.ip":"192.168.251.17", "event.type":"rest", "event.action":"authentication_success", "authentication.type":"REALM", "user.name":"elastic", "user.realm":"reserved", "origin.type":"rest", "origin.address":"[::1]:52490", "realm":"reserved", "url.path":"/shukla_test/_doc/2", "request.method":"POST", "request.body":" {\r\n "firstname": "Krishna",\r\n "lastname": "kumar"\r\n}", "request.id":"qaaUAg8sQKedKKrkcia4Xw"}

```

About this request:

```auto
POST /shukla_test/_doc/2
{
  "firstname": "Krishna",
  "lastname": "kumar"
}

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 10:26am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/10 "2023-07-27T10:26:19Z")

</div>

Note for @ashishshukla and @Subrato1

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 10:27am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/11 "2023-07-27T10:27:33Z")

</div>

As you can see in the logs, the event logged is a `authentication_success`. It's not a trace of the execution of the `_search`.

---

<div class="post-metadata">

**Author:** ![Subrato1](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Post date:** [July 27, 2023, 10:40am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/12 "2023-07-27T10:40:52Z")

</div>

Thanks For your Suggestion, I am able to understand.

Can you please tell me how to execute the SQL and EQL queries for Elasticsearch??

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/13 "2023-07-27T12:43:41Z")

</div>

Please open a new discussion as this one is solved I believe.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2023, 12:44pm UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/14 "2023-08-24T12:44:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
