# Elasticsearch is logging sensitive infrastructure information

**URL:** <https://discuss.elastic.co/t/elasticsearch-is-logging-sensitive-infrastructure-information/376761>\
**Category:** Elastic Search\
**Created:** [April 3, 2025, 5:51pm UTC](https://discuss.elastic.co/t/elasticsearch-is-logging-sensitive-infrastructure-information/376761 "2025-04-03T17:51:53Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Daniel\_Abadi](https://avatars.discourse-cdn.com/v4/letter/d/57b2e6/32.png) [@Daniel\_Abadi](https://discuss.elastic.co/u/Daniel_Abadi)\
**Post date:** [April 4, 2025, 11:21am UTC](https://discuss.elastic.co/t/elasticsearch-is-logging-sensitive-infrastructure-information/376761/4 "2025-04-04T11:21:12Z")

</div>

Of course! We have a platform where users can develop code. We use Elastic as a search engine, and they can perform queries, request object reindexing, among other actions. The issue is that we need to display certain logs to them since they need insights to understand potential issues in code execution. However, some logs end up exposing the Elastic address to the end user, which could compromise our security.

In this specific case, the user is using these fields in searches, which is generating the log and exposing our infrastructure. There are other similar cases as well, such as the following:

```auto
method [POST], host [http://address:9200/], URI [/5aa99e9e62edb97e8ca44888.638f55b514d6f675dce3d176/_search], status line [HTTP/1.1 500 Internal Server Error]  
{"error":{"root_cause":[{"type":"null_pointer_exception","reason":"Cannot invoke "java.lang.Integer.intValue()" because the return value of "org.elasticsearch.search.aggregations.bucket.composite.CompositeValuesCollectorQueue.top()" is null"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"idx.10.5aa99e9e62edb97e8ca44888.638f55b514d6f675dce3d176","node":"NH0bnj57RhiC5g2yTBQa8Q","reason":{"type":"null_pointer_exception","reason":"Cannot invoke "java.lang.Integer.intValue()" because the return value of "org.elasticsearch.search.aggregations.bucket.composite.CompositeValuesCollectorQueue.top()" is null"}}],"caused_by":{"type":"null_pointer_exception","reason":"Cannot invoke "java.lang.Integer.intValue()" because the return value of "org.elasticsearch.search.aggregations.bucket.composite.CompositeValuesCollectorQueue.top()" is null","caused_by":{"type":"null_pointer_exception","reason":"Cannot invoke "java.lang.Integer.intValue()" because the return value of "org.elasticsearch.search.aggregations.bucket.composite.CompositeValuesCollectorQueue.top()" is null"}}},"status":500}.

```

It's a situation similar to the one in the link below, but with the difference that I would like to mask our address in some way. We are using Elastic 7 and 8 at the same time while migrating to version 8.

> [@Disable specific deprecation warnings](https://discuss.elastic.co/t/disable-specific-deprecation-warnings/292678/3):
>
> Thanks for your reply, @ritchierich. We're not using Kibana or any other component of the Elastic Stack. The warning message is logged by the [Java High Level REST client](https://www.elastic.co/guide/en/elasticsearch/client/java-rest/current/java-rest-high.html) because the Elasticsearch node sends it in its response (Warning HTTP response header) and I want to know how to disable the generation of this warning on the Elasticsearch node. wink I'd also be fine with disabling the log message for this particular deprecation warning in the client, but I didn't find any configuration set…

Thank you very much for your attention. (Legal ver um brasileiro aqui)

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-is-logging-sensitive-infrastructure-information/376761)._
