# Does Elasticsearch capture audit logs for Query DSL, EQL and SQL or Not?

**URL:** <https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398>\
**Category:** Elasticsearch\
**Created:** [July 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398 "2023-07-27T08:07:11Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2023, 8:59am UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398/2 "2023-07-27T08:59:02Z")

</div>

No. The list of events which could be captured by the audit logs is here: [Audit events | Elasticsearch Guide [8.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-event-types.html)

But you can use slow logs for this: [Slow Log | Elasticsearch Guide [8.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.9/index-modules-slowlog.html). I think that using `0` as the threshold will log everything. But be careful as it will be very verbose.

---

_[View the full topic](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398)._
