# How to check kibana user searches

**URL:** <https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369>\
**Category:** Kibana\
**Created:** [January 16, 2016, 5:18am UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369 "2016-01-16T05:18:15Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![thunderbirdgit](https://avatars.discourse-cdn.com/v4/letter/t/ea666f/32.png) [@thunderbirdgit](https://discuss.elastic.co/u/thunderbirdgit)\
**Post date:** [January 16, 2016, 5:18am UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/1 "2016-01-16T05:18:15Z")

</div>

We are evaluating ELK stack for log analysis and visualization

ES 2.x,  
Logstash2.1  
and Kibana 4.

Does anyone happen to know how to track the user search queries made on kibana search bar. I am more interested to know about the non-saved searches from the user.  
I understand Kibana stores the search queries , dashboards and visualization in .kibana index.  
Is there a way to pull what the user had searched from kibana interface?

Can you help to understand with an example if thats possible to pull out from ES indexes?

---

<div class="post-metadata">

**Author:** ![thunderbirdgit](https://avatars.discourse-cdn.com/v4/letter/t/ea666f/32.png) [@thunderbirdgit](https://discuss.elastic.co/u/thunderbirdgit)\
**Post date:** [January 16, 2016, 4:22pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/2 "2016-01-16T16:22:09Z")

</div>

Highly appreciate any inputs

---

<div class="post-metadata">

**Author:** ![thunderbirdgit](https://avatars.discourse-cdn.com/v4/letter/t/ea666f/32.png) [@thunderbirdgit](https://discuss.elastic.co/u/thunderbirdgit)\
**Post date:** [January 19, 2016, 7:01pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/3 "2016-01-19T19:01:46Z")

</div>

I assume there is no solution to this?

---

<div class="post-metadata">

**Author:** ![Court](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/court/32/6640_2.png) [@Court](https://discuss.elastic.co/u/Court)\
**Post date:** [January 19, 2016, 9:20pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/4 "2016-01-19T21:20:39Z")

</div>

While there isn't a specific way to tie into the act of using the search bar in the Kibana UI, you could examine your standard web server access logs to track search requests to elasticsearch. Kibana proxies searches directly to elasticsearch, so you could look at the access logs for your _kibana_ webserver to see the searches to elasticsearch.

---

<div class="post-metadata">

**Author:** ![thunderbirdgit](https://avatars.discourse-cdn.com/v4/letter/t/ea666f/32.png) [@thunderbirdgit](https://discuss.elastic.co/u/thunderbirdgit)\
**Post date:** [January 19, 2016, 11:52pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/5 "2016-01-19T23:52:57Z")

</div>

Thanks for the reply !! We are not using any web server other than nginx to reverse proxy kibana. However, nginx doesnt help to track the user search on the kibana search bar. All i can see is few GET and POST methods

---

<div class="post-metadata">

**Author:** ![Court](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/court/32/6640_2.png) [@Court](https://discuss.elastic.co/u/Court)\
**Post date:** [January 20, 2016, 3:27pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/6 "2016-01-20T15:27:25Z")

</div>

Every time a person searches in Kibana, it results in a couple of HTTP requests to the Kibana backend which then proxy to elasticsearch. The request you want to look at is the "msearch" request.

On my local kibana setup, when I filter my data based on the extension "jpg", I get the following request:

POST [http://localhost:5601/elasticsearch/\_msearch?timeout=0&ignore\_unavailable=true&preference=1453303185156](http://localhost:5601/elasticsearch/_msearch?timeout=0&ignore_unavailable=true&preference=1453303185156)  
{"index":["logstash-2016.01.20"],"ignore\_unavailable":true}  
{"highlight":{"pre\_tags":["@kibana-highlighted-field@"],"post\_tags":["@/kibana-highlighted-field@"],"fields":{"_":{}},"require\_field\_match":false,"fragment\_size":2147483647},"query":{"filtered":{"query":{"query\_string":{"query":"_","analyze\_wildcard":true}},"filter":{"bool":{"must":[{"query":{"match":{"extension":{"query":"jpg","type":"phrase"}}}},{"range":{"@timestamp":{"gte":1453302324311,"lte":1453303224311,"format":"epoch\_millis"}}}],"must\_not":[]}}}},"size":500,"sort":[{"@timestamp":{"order":"desc","unmapped\_type":"boolean"}}],"aggs":{"2":{"date\_histogram":{"field":"@timestamp","interval":"30s","time\_zone":"America/New\_York","min\_doc\_count":0,"extended\_bounds":{"min":1453302324308,"max":1453303224309}}}},"fields":["\*","\_source"],"script\_fields":{},"fielddata\_fields":["@timestamp","utc\_time","relatedContent.article:modified\_time","relatedContent.article:published\_time"]}

As you can see, that post body includes both the "filters" and the "query" that are used in my search via the search and filter bars in Kibana.

---

<div class="post-metadata">

**Author:** ![harshini](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@harshini](https://discuss.elastic.co/u/harshini)\
**Post date:** [January 20, 2016, 6:03pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/7 "2016-01-20T18:03:58Z")

</div>

We had achieved this audit feature via a proxy servlet - all the requests were intercepted by the proxy to check if its a search query and accordingly audited.

---

<div class="post-metadata">

**Author:** ![thunderbirdgit](https://avatars.discourse-cdn.com/v4/letter/t/ea666f/32.png) [@thunderbirdgit](https://discuss.elastic.co/u/thunderbirdgit)\
**Post date:** [January 20, 2016, 6:26pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/8 "2016-01-20T18:26:35Z")

</div>

Thanks Court for the detaield investigation.. I do see POST requests on my nginx access log, however i dont see detailed query parameters logged in the logs.

x.x.x.x - - [20/Jan/2016:10:08:29 -0800] "POST /elasticsearch/\_msearch?timeout=0&ignore\_unavailable=true&preference=1453314159028 HTTP/1.1" 200 1544 "[http://hostname/app/kibana](http://hostname/app/kibana)" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36" "-"

---

<div class="post-metadata">

**Author:** ![Court](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/court/32/6640_2.png) [@Court](https://discuss.elastic.co/u/Court)\
**Post date:** [January 20, 2016, 6:39pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/9 "2016-01-20T18:39:06Z")

</div>

I've never done it myself, but I'm pretty sure you can configure nginx to log post bodies in access logs.

---

<div class="post-metadata">

**Author:** ![thunderbirdgit](https://avatars.discourse-cdn.com/v4/letter/t/ea666f/32.png) [@thunderbirdgit](https://discuss.elastic.co/u/thunderbirdgit)\
**Post date:** [January 21, 2016, 3:48am UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/10 "2016-01-21T03:48:54Z")

</div>

I had to explicitly add request\_body to NGINX log\_format to gather POST request parameters. I can see the query string now. Thanks much for the pointer.

x.x.x.x - - [20/Jan/2016:19:29:10 -0800] "POST /elasticsearch/\_msearch?timeout=0&ignore\_unavailable=true&preference=1453347750129 HTTP/1.1" "{\x22index\x22:[\x22test-logs\x22],\x22ignore\_unavailable\x22:true}\x0A{\x22size\x22:500,\x22sort\x22:[{\x22@timestamp\x22:{\x22order\x22:\x22desc\x22,\x22unmapped\_type\x22:\x22boolean\x22}}],\x22query\x22:{\x22filtered\x22:{\x22query\x22:{\x22query\_string\x22:{\x22query\x22:\x22testing\x22,\x22analyze\_wildcard\x22:true}},\x22filter\x22:{\x22bool\x22:{\x22must\x22:[{\x22range\x22:{\x22@timestamp\x22:{\x22gte\x22:1448163803080,\x22lte\x22:1453347803080,\x22format\x22:\x22epoch\_millis\x22}}}],\x22must\_not\x22:[]}}}},\x22highlight\x22:{\x22pre\_tags\x22:[\x22@kibana-highlighted-field@\x22],\x22post\_tags\x22:[\x22@/kibana-highlighted-field@\x22],\x22fields\x22:{\x22\*\x22:{}},\x22require\_field\_match\x22:false,\x22fragment\_size\x22:2147483647},\x22aggs\x22:{\x222\x22:{\x22date\_histogram\x22:{\x22field\x22:\x22@timestamp\x22,\x22interval\x22:\x221d\x22,\x22time\_zone\x22:\x22GMT\x22,\x22min\_doc\_count\x22:0,\x22extended\_bounds\x22:{\x22min\x22:1448163803080,\x22max\x22:1453347803080}}}},\x22fields\x22:[\x22\*\x22,\x22\_source\x22],\x22script\_fields\x22:{},\x22fielddata\_fields\x22:[\x22@timestamp\x22]}\x0A"200 1510 "[http://hostname/app/kibana](http://hostname/app/kibana)" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36" "-"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:04pm UTC](https://discuss.elastic.co/t/how-to-check-kibana-user-searches/39369/11 "2017-07-06T14:04:35Z")

</div>


