# Exclude user from security audit logging? (logstash's elasticsearch output user)

**URL:** <https://discuss.elastic.co/t/exclude-user-from-security-audit-logging-logstashs-elasticsearch-output-user/86881>\
**Category:** Elasticsearch\
**Created:** [May 24, 2017, 1:16am UTC](https://discuss.elastic.co/t/exclude-user-from-security-audit-logging-logstashs-elasticsearch-output-user/86881 "2017-05-24T01:16:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Myles](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Myles](https://discuss.elastic.co/u/Myles)\
**Post date:** [May 24, 2017, 1:16am UTC](https://discuss.elastic.co/t/exclude-user-from-security-audit-logging-logstashs-elasticsearch-output-user/86881/1 "2017-05-24T01:16:23Z")

</div>

Hey Guys,

I would be very interested in a way to exclude the user I use to authenticate my elasticsearch output in logstash from the security auditing feature. The auditing is very helpful and I want all the audit events turned on. The problem is when I have 10k EPS coming from my logstash cluster into my elasticsearch cluster with each bulk operation being audit logged. Is there either a way to exclude users from audit logging or just a better way to output to elasticsearch from logstash to avoid the audit logging of said operation in the first place?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 1:16am UTC](https://discuss.elastic.co/t/exclude-user-from-security-audit-logging-logstashs-elasticsearch-output-user/86881/2 "2017-06-21T01:16:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
