# Find source of request using invalid API Key

**URL:** <https://discuss.elastic.co/t/find-source-of-request-using-invalid-api-key/366757>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 18, 2024, 8:58pm UTC](https://discuss.elastic.co/t/find-source-of-request-using-invalid-api-key/366757 "2024-09-18T20:58:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steve\_Foster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_foster/32/125583_2.png) [@Steve\_Foster](https://discuss.elastic.co/u/Steve_Foster)\
**Post date:** [September 18, 2024, 8:58pm UTC](https://discuss.elastic.co/t/find-source-of-request-using-invalid-api-key/366757/1 "2024-09-18T20:58:51Z")

</div>

Hi,

I've seen these in the logs for a while now but I've been able to find a way to show where the request is coming from.

```auto
Authentication using apikey failed - unable to find apikey with id <ID>

```

Any suggestions?

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [September 20, 2024, 6:58am UTC](https://discuss.elastic.co/t/find-source-of-request-using-invalid-api-key/366757/2 "2024-09-20T06:58:44Z")

</div>

Hey @Steve_Foster !

If you have a [subscription](https://www.elastic.co/subscriptions), you can use [audit logs](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html) for that.

Other options would include:

- Using the [REST request tracer](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html#http-rest-request-tracer). This will add a significant amount of logging, and is not recommended for heavily loaded clusters
- Use a reverse proxy in front of your Elasticsearch cluster, that logs the requests and connection origins.

Hope that helps!
