# Elasticsearch Audit Logs decipher

**URL:** <https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652>\
**Category:** Elasticsearch\
**Created:** [November 21, 2023, 4:10pm UTC](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652 "2023-11-21T16:10:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brian-cf1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Post date:** [November 21, 2023, 4:10pm UTC](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652/1 "2023-11-21T16:10:19Z")

</div>

I am looking at the Elasticsearch Audit logs and i am getting an authentication denied for User Elastic, why would our servers be authenticating against our Elasticsearch nodes when we are getting logs from the beats and there are indexes tied to the logs

What is this request need to track it down as it is flooding our logs

```auto
{"type":"audit", "timestamp":"2023-11-20T20:56:24,845+0000", "node.id":"{NodeID}", "event.type":"rest", "event.action":"authentication_failed", "user.name":"elastic", "origin.type":"rest", "origin.address":"{IPADDRESS}:55506", "url.path":"/", "request.method":"GET", "request.id":"{REQUESTID}"}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 21, 2023, 4:24pm UTC](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652/2 "2023-11-21T16:24:15Z")

</div>

The `url.path` shows you what was the endpoint of this request, since it is showing `/`, this is the same as `curl https://your-host:9200`.

Do you now the ip address in the `origin.address` field?

Is your Instance exposed to the public internet?

---

<div class="post-metadata">

**Author:** ![Brian-cf1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Post date:** [November 21, 2023, 4:33pm UTC](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652/3 "2023-11-21T16:33:52Z")

</div>

Yeah , so these logs are coming from a data node, and the origin IP is ( all over the place ) but this specific instance is coming from our coordinating node, ( has multiple beats , kibana , elasticsearch on it ) and no its internal

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2023, 4:34pm UTC](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652/4 "2023-12-19T16:34:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
