# Find out who is running task

**URL:** <https://discuss.elastic.co/t/find-out-who-is-running-task/379786>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 3, 2025, 5:47pm UTC](https://discuss.elastic.co/t/find-out-who-is-running-task/379786 "2025-07-03T17:47:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 3, 2025, 5:47pm UTC](https://discuss.elastic.co/t/find-out-who-is-running-task/379786/1 "2025-07-03T17:47:08Z")

</div>

I am trying to find out who is running a task in elasticsearch  
I did use \_task api with different options like

```auto
GET /_tasks/oYXgEVBgQoGToxFxhVoA3g:198142212
GET /_tasks/oYXgEVBgQoGToxFxhVoA3g:198143553

GET _cat/tasks?detailed?
GET /_cat/tasks?v&detailed=true

GET _tasks?detailed=true&actions=*

GET _tasks?detailed=true&group_by=parents

```

None of the output has any user info. headers has only task\_id  
I have basic authantication enable means anyone who want to run anything needs to provide user/password. this is basic \_xpack security feature.

is there way to find out? this installation is free version hence I can't turn on audit log.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 7, 2025, 11:03am UTC](https://discuss.elastic.co/t/find-out-who-is-running-task/379786/2 "2025-07-07T11:03:58Z")

</div>

Hi @elasticforme,

This [older thread](https://discuss.elastic.co/t/how-to-identify-specific-users-who-are-submitting-slowlog-queries/312120) does share some examples, but the main thing is that you can track the source of requests using the [`X-Opaque-Id` HTTP header](https://www.elastic.co/guide/en/elasticsearch/reference/8.18/api-conventions.html#x-opaque-id) if you pass the information to Elasticsearch. That can then be accessed via things like the slow logs.

Hope that helps.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 7, 2025, 10:14pm UTC](https://discuss.elastic.co/t/find-out-who-is-running-task/379786/3 "2025-07-07T22:14:49Z")

</div>

hmm this won't help me much. because most all client are using python to connect.  
but this is good idea for any rest query

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 8, 2025, 8:41am UTC](https://discuss.elastic.co/t/find-out-who-is-running-task/379786/4 "2025-07-08T08:41:26Z")

</div>

@elasticforme it is possible to add headers to the Python connection, as covered [here](https://elasticsearch-py.readthedocs.io/en/v8.18.1/api/elasticsearch.html) in the Python client documentation:

 ![Screenshot 2025-07-08 at 09.39.49](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3a86690e8d38e84b60c79e395e099c2f67be072a.jpeg)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 8, 2025, 8:07pm UTC](https://discuss.elastic.co/t/find-out-who-is-running-task/379786/5 "2025-07-08T20:07:18Z")

</div>

just for someone who might be looking this.

I did this in python

```auto
script_name = os.path.basename(sys.argv[0])
es = Elasticsearch(elastic_hostnames, http_auth=(elastic_admin_user, elastic_admin_passwd),
                               request_timeout=120, max_retries=3,
                               retry_on_timeout=True,
                               sniff_on_node_failure=True,
                               headers={"X-Opaque-Id": script_name})

```

and I now has headers show up as python script name.
