# How to confirm audit logging is enabled

**URL:** <https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888>\
**Category:** Elasticsearch\
**Created:** [May 13, 2021, 7:54am UTC](https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888 "2021-05-13T07:54:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![knagasri](https://avatars.discourse-cdn.com/v4/letter/k/47e85d/32.png) [@knagasri](https://discuss.elastic.co/u/knagasri)\
**Post date:** [May 13, 2021, 7:54am UTC](https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888/1 "2021-05-13T07:54:33Z")

</div>

I had deployed elasticsearch-operator(1.3.0) with elasticsearch 7.9.0 in GKE. I have used below line in my elasticsearch.yaml to enable audit logging:

xpack.security.audit.enabled: true

As per the documentation([Enabling audit logging | Elasticsearch Guide [7.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/enable-audit-logging.html)), there will be some file "clustername\>\_audit.json" like this if I do exec into the pod. But I am not able to see that file.

can anyone suggest , is there anything that I need to add.

---

<div class="post-metadata">

**Author:** ![knagasri](https://avatars.discourse-cdn.com/v4/letter/k/47e85d/32.png) [@knagasri](https://discuss.elastic.co/u/knagasri)\
**Post date:** [May 17, 2021, 3:54pm UTC](https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888/2 "2021-05-17T15:54:03Z")

</div>

Can anyone tell whether it will be supporting for free users or only for subscribed users.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 17, 2021, 4:15pm UTC](https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888/3 "2021-05-17T16:15:59Z")

</div>

Audit logging requires a commercial subscription.

---

<div class="post-metadata">

**Author:** ![knagasri](https://avatars.discourse-cdn.com/v4/letter/k/47e85d/32.png) [@knagasri](https://discuss.elastic.co/u/knagasri)\
**Post date:** [May 19, 2021, 6:40am UTC](https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888/4 "2021-05-19T06:40:56Z")

</div>

Okay. Thanks @Christian_Dahlqvist for the information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2021, 6:41am UTC](https://discuss.elastic.co/t/how-to-confirm-audit-logging-is-enabled/272888/5 "2021-06-16T06:41:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
