# How to index Elasticsearch security audit events in 7.0?

**URL:** <https://discuss.elastic.co/t/how-to-index-elasticsearch-security-audit-events-in-7-0/177658>\
**Category:** Elasticsearch\
**Created:** [April 19, 2019, 6:34pm UTC](https://discuss.elastic.co/t/how-to-index-elasticsearch-security-audit-events-in-7-0/177658 "2019-04-19T18:34:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Vasquez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_vasquez/32/22088_2.png) [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Post date:** [April 19, 2019, 6:34pm UTC](https://discuss.elastic.co/t/how-to-index-elasticsearch-security-audit-events-in-7-0/177658/1 "2019-04-19T18:34:07Z")

</div>

So I've just recently upgraded to 7.0 from 6.7 and had to take out:  
`xpack.security.audit.outputs: [index, log]`

from the elasticsearch.yml config file due to deprecation in 7.0?

As I understand now security audit event are now logged to a json log file. Whats the proper way to index this? Filebeat? Logstash? I don't understand why they took this feature away.. Broke all my security audit visualizations/dashboards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2019, 6:34pm UTC](https://discuss.elastic.co/t/how-to-index-elasticsearch-security-audit-events-in-7-0/177658/2 "2019-05-17T18:34:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
