# How to enable kibana audit logs

**URL:** <https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [March 12, 2020, 6:39am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261 "2020-03-12T06:39:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [March 12, 2020, 6:39am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/1 "2020-03-12T06:39:17Z")

</div>

how do i enable kibana audit logs?  
Can anyone please tell me the steps to enable it in linux server.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 5:01pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/2 "2020-03-12T17:01:26Z")

</div>

You just need to set `xpack.security.audit.enabled` as True in your Kibana.yml file. That is all.

---

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [March 12, 2020, 5:31pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/3 "2020-03-12T17:31:42Z")

</div>

I have enabled it. But the data is not written to the audit file. Does it require any license version  
?

---

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [March 12, 2020, 5:35pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/4 "2020-03-12T17:35:53Z")

</div>

Does it requires any configuration settings of elastic search and filebeat settings to be changed. I have been trying this from 10days but the audit logs are empty . Can you please provide me the solution.  
Thanks

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 11:49pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/5 "2020-03-12T23:49:50Z")

</div>

What do you have set as `logging.dest:` in Kibana.yml? If that doesn't exist, it will write everything to stdout.

---

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [March 13, 2020, 2:45am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/6 "2020-03-13T02:45:00Z")

</div>

yes it has been set to stdout and commented it as i.e #logging.dest: stdout.  
so where will these logs will be stored. can i set it to logs path and remove the comment of logging.dest?

---

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [March 13, 2020, 5:02am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/7 "2020-03-13T05:02:38Z")

</div>

kibana audit logs and std(out & err)logs are different right?  
I can see log\_kibana.out and log\_kibana.err files in kibana folder. But what i want is audit logs which include audit events like access\_granted, anonymous\_access\_denied, authentication\_failed, connection\_denied, tampered\_request, run\_as\_denied, run\_as\_granted.  
Can you please guide me how to enable them . And in which file and where will this output gets generated .

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 13, 2020, 12:23pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/8 "2020-03-13T12:23:25Z")

</div>

The kibana audit logs will be in the same location.  
[https://www.elastic.co/guide/en/kibana/current/xpack-security-audit-logging.html](https://www.elastic.co/guide/en/kibana/current/xpack-security-audit-logging.html)  
Audit logging uses the standard Kibana logging output, which can be configured in the `kibana.yml`

There are some different elasticsearch audit logs as well, which are enabled differently and log in a different location.  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html)

---

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [March 14, 2020, 11:35am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/9 "2020-03-14T11:35:06Z")

</div>

Thanks for your reply.  
Does kibana or elasticsearch Audit logging requires any license subscriptions like gold or platinum license type ? Or this configuration `xpack.security.audit.enabled` to `true` in yml file is enough to write audit logs?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 17, 2020, 1:05pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/10 "2020-03-17T13:05:26Z")

</div>

Indeed it needs to be Gold or Platinum license. Also, it works with the trial one as well.

---

<div class="post-metadata">

**Author:** ![mounikasony](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@mounikasony](https://discuss.elastic.co/u/mounikasony)\
**Post date:** [April 6, 2020, 1:06pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/11 "2020-04-06T13:06:57Z")

</div>

We are using a Basic version but i don't see any changes impacting.  
Where should i check them in my server?  
Will the audit logs will work only for gold or platinum license only?  
Can you please answer the question @Marius_Dragomir

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2020, 1:07pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-audit-logs/223261/12 "2020-05-04T13:07:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
