# How to lower the burden of audit log

**URL:** <https://discuss.elastic.co/t/how-to-lower-the-burden-of-audit-log/167956>\
**Category:** Elasticsearch\
**Created:** [February 12, 2019, 5:30am UTC](https://discuss.elastic.co/t/how-to-lower-the-burden-of-audit-log/167956 "2019-02-12T05:30:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ivanyu](https://avatars.discourse-cdn.com/v4/letter/i/41988e/32.png) [@ivanyu](https://discuss.elastic.co/u/ivanyu)\
**Post date:** [February 12, 2019, 5:30am UTC](https://discuss.elastic.co/t/how-to-lower-the-burden-of-audit-log/167956/1 "2019-02-12T05:30:18Z")

</div>

Dear,

My cluster broke down several times and the elasticsearch log says:  
failed to index audit event：[access\_granted]. internal queue is full. which may be caused by a high indexing rate or issue with the destination

And after I disable the audit, the cluster is stable until now.  
But because of company policy, we need to record the audit.  
So my question is how to solve the above problem? Is it helpful to increase some of the internal queue or just send the audit log to another elasticsearch cluster?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2019, 5:30am UTC](https://discuss.elastic.co/t/how-to-lower-the-burden-of-audit-log/167956/2 "2019-03-12T05:30:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
