# Elasticsearchへのアクセス確認について

**URL:** <https://discuss.elastic.co/t/elasticsearch/81948>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [April 11, 2017, 9:43am UTC](https://discuss.elastic.co/t/elasticsearch/81948 "2017-04-11T09:43:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yossy](https://avatars.discourse-cdn.com/v4/letter/y/b2d939/32.png) [@yossy](https://discuss.elastic.co/u/yossy)\
**Post date:** [April 11, 2017, 9:43am UTC](https://discuss.elastic.co/t/elasticsearch/81948/1 "2017-04-11T09:43:25Z")

</div>

動作検証をする上で、Elasticsearch（各ノード）へのアクセスをログから確認したいと思っております。

ログの出力先ディレトリに、"クラスタ名\_access.log"というファイルがありますので、出力自体は可能だと考えておりますが、コンフィグでどのパラメータを設定すれば出力されるでしょうか？

また、パフォーマンステスト時に各ノード毎のアクセス数も確認したいのですが、こちらはKibanaで確認可能でしょうか？

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [April 17, 2017, 9:40am UTC](https://discuss.elastic.co/t/elasticsearch/81948/2 "2017-04-17T09:40:43Z")

</div>

X-Packをインストールしていませんか？  
[https://www.elastic.co/guide/en/x-pack/current/auditing.html](https://www.elastic.co/guide/en/x-pack/current/auditing.html)

こちらの機能になります。Elasticsearch本体の機能ではありません。  
インデックスもできるのでやろうと思えばKibanaで確認可能ですが、そもそもの用途とは別物ですね。

また、Elasticsearchは複数マシンでクラスタを組んでいる場合には分散で検索します。  
仕組みなどはこちらになります。  
[https://www.elastic.co/guide/en/elasticsearch/guide/current/distributed-search.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/distributed-search.html)  
インデックスの構成などによってどのように分散検索が実行されるかもあるので、負荷の状況とかは変わってくるんじゃないかと思いますが。

---

<div class="post-metadata">

**Author:** ![yossy](https://avatars.discourse-cdn.com/v4/letter/y/b2d939/32.png) [@yossy](https://discuss.elastic.co/u/yossy)\
**Post date:** [April 18, 2017, 2:13am UTC](https://discuss.elastic.co/t/elasticsearch/81948/3 "2017-04-18T02:13:58Z")

</div>

ご確認ありがとうございます。

下記の設定をして、アクセスログに出力できることを確認できました。

* * *

## xpack.security.audit.enabled: true xpack.security.audit.outputs: [index, logfile]

監査用だからだと思いますが、けっこうな量が出力されますが、"クライアントからのアクセス（検索や登録などの処理）のみ"に絞ることは可能でしょうか？

ご提示頂いたリンクから公式ドキュメントを確認していますが、教えて頂けますと幸いです。

当方で確認したいアクセスログとしましては、”クライアントからの検索1件につき、1件のアクセスログ”というように考えておりますが、実際に1件の検索でアクセスしましたところ、下記のように複数件のログが出力されます。

[2017-04-18T10:57:35,249] [transport] [access\_granted] origin\_type=[transport], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search], indices=[index\_name], request=[SearchRequest]  
[2017-04-18T10:57:35,253] [transport] [access\_granted] origin\_type=[transport], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search], indices=[index\_name], request=[SearchRequest]  
[2017-04-18T10:57:35,254] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search[phase/query]], indices=[index\_name], request=[ShardSearchTransportRequest]  
[2017-04-18T10:57:35,255] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search[phase/query]], indices=[index\_name], request=[ShardSearchTransportRequest]  
[2017-04-18T10:57:35,257] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search[phase/query]], indices=[index\_name], request=[ShardSearchTransportRequest]  
[2017-04-18T10:57:35,258] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search[phase/query]], indices=[index\_name], request=[ShardSearchTransportRequest]  
[2017-04-18T10:57:35,263] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search[phase/query]], indices=[index\_name], request=[ShardSearchTransportRequest]  
[2017-04-18T10:57:35,306] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)], principal=[xxxxx], action=[indices:data/read/search[phase/fetch/id]], indices=[index\_name], request=[ShardFetchSearchRequest]

また、他にも下記のようにヘルスチェックのログも出力されており、こちらも出力しないようにしたいと考えています。

[2017-04-18T11:03:27,050] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[kibana], action=[cluster:monitor/nodes/info], request=[NodesInfoRequest]  
[2017-04-18T11:03:27,050] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[kibana], action=[cluster:monitor/nodes/info[n]], request=[NodeInfoRequest]  
[2017-04-18T11:03:27,052] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[kibana], action=[cluster:monitor/health], indices=[.kibana], request=[ClusterHealthRequest]

---

<div class="post-metadata">

**Author:** ![st1t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/st1t/32/9188_2.png) [@st1t](https://discuss.elastic.co/u/st1t)\
**Post date:** [April 18, 2017, 3:55am UTC](https://discuss.elastic.co/t/elasticsearch/81948/4 "2017-04-18T03:55:53Z")

</div>

> 監査用だからだと思いますが、けっこうな量が出力されますが、"クライアントからのアクセス（検索や登録などの処理）のみ"に絞ることは可能でしょうか？

@johtaniさんが記載されているリンク先のAudit Event TypesやAudit Event Attributesでは実現しようとしていることが難しいということでしょうか。  
恐らくxpack.security.audit.logfile.events.includeやxpack.security.audit.logfile.events.excludeで解決できるかと思うので、  
まずは色々試してログ出力内容を実際に確認してみるのが良いかと思います。  
英語表記はGoogle Chromeの翻訳機能を使うと理解しやすいかなと。

---

<div class="post-metadata">

**Author:** ![yossy](https://avatars.discourse-cdn.com/v4/letter/y/b2d939/32.png) [@yossy](https://discuss.elastic.co/u/yossy)\
**Post date:** [April 18, 2017, 6:00am UTC](https://discuss.elastic.co/t/elasticsearch/81948/5 "2017-04-18T06:00:38Z")

</div>

ありがとうございます。

試してみます。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2017, 6:15am UTC](https://discuss.elastic.co/t/elasticsearch/81948/6 "2017-05-16T06:15:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
