# Getting incomplete request body in Elasticsearch audit log

**URL:** <https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 8, 2024, 6:39am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543 "2024-01-08T06:39:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashishshukla](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Post date:** [January 8, 2024, 6:39am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543/1 "2024-01-08T06:39:02Z")

</div>

I have executed few security APIs , for those I am getting incomplete request body in Elasticsearch Audit log. Below are the example:

**Query 1:**

POST /\_security/oauth2/token  
{  
"grant\_type": "refresh\_token",  
**"refresh\_token": "vLBPvmAB6KvwvJZr27cS"**  
}

**Audit Log:**  
{"type":"audit", "timestamp":"2023-12-29T10:48:51,458+0530", "cluster.uuid":"N4A0f0IaSEmDKajj14TcPw", "node.name":"node-1", "Home | NODE.ID ":"IiljWrd3Tv2IghTMopvNaA", "host.name":"DESKTOP-S1VTHGS", "host.ip":"9.43.27.251", "event.type":"rest", "event.action":"authentication\_success", "authentication.type":"REALM", "user.name":"elastic", "user.realm":"reserved", "origin.type":"rest", "origin.address":"192.168.29.126:51704", "realm":"reserved", "url.path":"/\_security/oauth2/token", "request.method":"POST", "request.body":"{"grant\_type":"refresh\_token"}", "request.id":"OjNA0oFQQUyxnNm7RAJsjA"}

**Concern-**  
( Here we can see in above audit log **"refresh\_token": "vLBPvmAB6KvwvJZr27cS"** this value is not getting in request body )

**Query 2:**

POST /\_security/oauth2/token  
{  
"grant\_type" : "password",  
"username" : "test\_admin",  
"password" : "x-pack-test-password"  
}

**Audit Log:**  
{"type":"audit", "timestamp":"2023-12-29T10:48:27,620+0530", "cluster.uuid":"N4A0f0IaSEmDKajj14TcPw", "node.name":"node-1", "Home | NODE.ID ":"IiljWrd3Tv2IghTMopvNaA", "host.name":"DESKTOP-S1VTHGS", "host.ip":"9.43.27.251", "event.type":"rest", "event.action":"authentication\_success", "authentication.type":"REALM", "user.name":"elastic", "user.realm":"reserved", "origin.type":"rest", "origin.address":"192.168.29.126:51704", "realm":"reserved", "url.path":"/\_security/oauth2/token", "request.method":"POST", "request.body":"{"grant\_type":"password","username":"test\_admin"}", "request.id":"wSTPJrfVQzGP\_oBIxuXOcA"}

**Concern-**  
( Here we can see in above audit log **"password" : "x-pack-test-password"** this value is not getting in request body )

Please suggest for the above concerns is there anyone we can see complete request body(including confidential data like "password" and "token" etc..) in audit log for above security APIs

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 8, 2024, 8:10am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543/2 "2024-01-08T08:10:38Z")

</div>

It is by design that sensitive data is not recorded in the audit log. There shouldn't be a good reason to log these things.

---

<div class="post-metadata">

**Author:** ![ashishshukla](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Post date:** [January 8, 2024, 8:41am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543/3 "2024-01-08T08:41:57Z")

</div>

thanks for update

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2024, 8:42am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543/4 "2024-02-05T08:42:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
