# Elasticsearch Not Logging Query Details Despite Enabling Audit Logs

**URL:** <https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [April 4, 2025, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790 "2025-04-04T12:37:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![kishorkumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorkumar/32/132930_2.png) [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Post date:** [April 4, 2025, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/1 "2025-04-04T12:37:08Z")

</div>

I have enabled the **xpack.security.audit.enabled: true** and also added  
**xpack.security.audit.logfile.events.emit\_request\_body: true** but when i query from postman but that does not seems to logging as i can only two streams

- logs-enterprise\_search.api-default
- logs-enterprise\_search.audit-default

both of them does not conatin the query info either

so how do i enable the logging of the elasticsearch for everyuser and index that's being queried by any method even api, or postman, or any other dev console etc. i need the logs for it with complete what query was performed and the query body and index details etc.\

#elasticsearch #Elastic Stack > Elasticsearch #Elastic Stack #elastic-stack-monitoring

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 4, 2025, 12:44pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/2 "2025-04-04T12:44:51Z")

</div>

As per the [subscriptions page](https://www.elastic.co/subscriptions) audit logging does require a commercial (or trial) license. Do you have this in place in your cluster?

---

<div class="post-metadata">

**Author:** ![kishorkumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorkumar/32/132930_2.png) [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Post date:** [April 4, 2025, 12:53pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/3 "2025-04-04T12:53:23Z")

</div>

Yes, i have the trail licence on elastic cloud trial licence and its entriprise

```auto
{
  "license": {
    "status": "active",
    "uid": "90db30a7-19e4-42e6-b1fc-c76567ada0e2",
    "type": "enterprise",
    "issue_date": "2023-03-02T00:00:00.000Z",
    "issue_date_in_millis": 1677715200000,
    "expiry_date": "2028-02-29T23:59:59.999Z",
    "expiry_date_in_millis": 1835481599999,
    "max_nodes": null,
    "max_resource_units": 100000,
    "issued_to": "Elastic Cloud",
    "issuer": "API",
    "start_date_in_millis": 1677628800000
  }
}

```

As i have created elastic cloud trail account and can be seen that elastic subscription.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/a/bad608bf467fa159eb49e3399f33c8e8940cbc63.png)

Elasticsearch YML Settings:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95a25ee0334ee4291a803285f6c5115c968ced20.png)

```auto
xpack.security.audit.enabled: true
xpack.security.audit.logfile.events.emit_request_body: true
xpack.security.audit.logfile.events.include: access_denied, access_granted, anonymous_access_denied, authentication_success, authentication_failed, connection_denied, tampered_request, run_as_denied, run_as_granted, security_config_change

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 5, 2025, 5:33am UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/4 "2025-04-05T05:33:01Z")

</div>

Did you enable the shipping of logs to a Monitoring cluster?

---

<div class="post-metadata">

**Author:** ![kishorkumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorkumar/32/132930_2.png) [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Post date:** [April 5, 2025, 9:17am UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/5 "2025-04-05T09:17:04Z")

</div>

Yes I have enable the shipping monitoring logs.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 6, 2025, 2:35pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/6 "2025-04-06T14:35:37Z")

</div>

Been a while since I set these... But I know logging the body is possible

`include` specifies a `list` so perhaps

FIXED SEE BELOW

---

<div class="post-metadata">

**Author:** ![kishorkumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorkumar/32/132930_2.png) [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Post date:** [April 6, 2025, 3:14pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/7 "2025-04-06T15:14:43Z")

</div>

Even o tried remove that but it doesn't seems to work.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 6, 2025, 4:50pm UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/8 "2025-04-06T16:50:18Z")

</div>

Here is what I used in the past ... you do not need to put them in the elasticsearch.yml use the `_cluster/settings` API

I would clear them out and use this... please check the correct names and setttings as this is a from last year

```auto
PUT /_cluster/settings
{
  "persistent" : {
    "cluster" : {
    "xpack" : {
      "security" : {
        "audit" : {
          "logfile" : {
            "events" : {
              "ignore_filters" : {
                "actions_policy" : {
                  "actions" : [
                    "indices:data/write/bulk*",
                    "indices:data/write/index:op_type/create",
                    "internal:*"
                  ]
                },
                "users_policy" : {
                  "users" : [
                    "found-*"
                  ]
                },
                "indices_policy" : {
                  "indices" : [
                    ".monitoring*",
                    "metricbeat*"
                  ]
                }
              },
              "emit_request_body" : "true",
              "include" : [
                "access_denied",
                "access_granted",
                "anonymous_access_denied",
                "authentication_failed",
                "connection_denied",
                "tampered_request",
                "run_as_denied",
                "run_as_granted",
                "security_config_change",
                "authentication_success"
              ]
            }
          }
        }
      }
    }
  }
}

```

You might need to tune it a bit

Also, exactly what version are you on?  
And exactly what components are you using?  
Are you using the old app search components or just plain elasticsearch? I think there's a disconnect somewhere

The more precise you are, the better we can help

---

<div class="post-metadata">

**Author:** ![kishorkumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorkumar/32/132930_2.png) [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Post date:** [April 7, 2025, 5:46am UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/10 "2025-04-07T05:46:56Z")

</div>

it's fixed. thanks for the help guys.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 7, 2025, 6:16am UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/11 "2025-04-07T06:16:18Z")

</div>

Hi @kishorkumar can You please provide what the fix was for you so people perhaps with the same issue can find the answer.

We did spend some time with you and this is community. We would appreciate it if you would let us know what the fix was for you.

Was it simply specifying the include as a list?

---

<div class="post-metadata">

**Author:** ![kishorkumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorkumar/32/132930_2.png) [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Post date:** [April 7, 2025, 6:59am UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790/12 "2025-04-07T06:59:17Z")

</div>

✅ Step-by-Step: Enable Audit Logs in Elasticsearch

1. **Update `elasticsearch.yml` with Audit Logging Settings**

On **all nodes** in the cluster, append the following lines to the `elasticsearch.yml` file:

If you are using cloud go the edit the cluster and click on manage extension then Add the following for all the settings in elasticsearch.yml

```auto
xpack.security.audit.enabled: true
xpack.security.audit.logfile.events.emit_request_body: true
xpack.security.audit.logfile.events.include: access_denied, access_granted, anonymous_access_denied, authentication_success, authentication_failed, connection_denied, tampered_request, run_as_denied, run_as_granted, security_config_change

```

⚠ **Important:**

- Do **not** wrap the `include` list with quotes or square brackets.

- Each event type is separated by a comma as raw YAML — exactly as shown.

- Save the file after editing.

- Restart Elasticsearch nodes on on-primses

3.create dataview for the datastream **elastic-cloud-logs-8**
