# Elasticsearch Auditing Files in docker container can not be found

**URL:** <https://discuss.elastic.co/t/elasticsearch-auditing-files-in-docker-container-can-not-be-found/200728>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [September 23, 2019, 4:22pm UTC](https://discuss.elastic.co/t/elasticsearch-auditing-files-in-docker-container-can-not-be-found/200728 "2019-09-23T16:22:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![apt-get\_install\_skil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apt-get_install_skil/32/115156_2.png) [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Post date:** [September 23, 2019, 4:22pm UTC](https://discuss.elastic.co/t/elasticsearch-auditing-files-in-docker-container-can-not-be-found/200728/1 "2019-09-23T16:22:35Z")

</div>

Hey there,

I run an Elasticsearch 7.3.0 6-node cluster on three machines (one coordinating-only and one mdi-node each) via docker-compose.  
I've set up security via certificates/pki.

Now I want to enable the auditing feature as described in [this guide](https://www.elastic.co/guide/en/elastic-stack-overview/7.3/auditing.html).

Therefore I set these settings in each elasticsearch service:

```
xpack.security.audit.enabled: "true"
xpack.security.audit.logfile.events.emit_request_body: "true"

```

As stated in the guide, a file with the pattern '\<clustername\>\_audit.json' should be generated in the logs directory.

However, there is no such file on any node when I jump into my containers via docker exec (only gc files).  
What do I miss here? Do I have to explicitely configure a logger for this?

---

<div class="post-metadata">

**Author:** ![apt-get\_install\_skil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apt-get_install_skil/32/115156_2.png) [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Post date:** [October 9, 2019, 10:09am UTC](https://discuss.elastic.co/t/elasticsearch-auditing-files-in-docker-container-can-not-be-found/200728/2 "2019-10-09T10:09:12Z")

</div>

Hey there,

I've talked about this issue with an experienced colleague. He told me that by default all elasticsearch events/messages, including the audit events, will be logged to the console/stdout of the container.

Can anyone confirm this information? Thanks!

---

<div class="post-metadata">

**Author:** ![MiTschMR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mitschmr/32/48254_2.png) [@MiTschMR](https://discuss.elastic.co/u/MiTschMR)\
**Post date:** [October 14, 2019, 6:17am UTC](https://discuss.elastic.co/t/elasticsearch-auditing-files-in-docker-container-can-not-be-found/200728/3 "2019-10-14T06:17:10Z")

</div>

Hi @apt-get_install_skil

I can confirm that Elasticsearch events and messages are logged to the console of the container. If you want to change this behaviour you have to edit the log4j2.properties file (well, I had to do this).

Hope this helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2019, 6:17am UTC](https://discuss.elastic.co/t/elasticsearch-auditing-files-in-docker-container-can-not-be-found/200728/4 "2019-11-11T06:17:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
