# How to see audit log in for my deployment in elastic cloud

**URL:** <https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257>\
**Category:** Elasticsearch\
**Created:** [July 26, 2023, 6:38am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257 "2023-07-26T06:38:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashishshukla](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Post date:** [July 26, 2023, 6:38am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257/1 "2023-07-26T06:38:26Z")

</div>

I have run the insert the data in Elasticsearch through rest call and once I went to Log and metrics inside the elastic cloud GUI ,I am unable to find audit logs , only I am getting server log, Please guide me regarding the same.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 26, 2023, 7:17am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257/3 "2023-07-26T07:17:42Z")

</div>

Have a look at: [How to set up monitoring | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-monitoring-setup.html#ec_enable_logs_and_metrics)

> Optionally, turn on [audit logging](https://www.elastic.co/guide/en/elasticsearch/reference/8.9/auditing-settings.html) to capture security-related events, such as authentication failures, refused connections, and data-access events through the proxy. To turn on audit logging, [edit your deployment’s elasticsearch.yml file](https://www.elastic.co/guide/en/cloud/current/ec-add-user-settings.html) to add these lines:
> 
> ```auto
> xpack.security.audit.enabled: true 
> # xpack.security.audit.logfile.events.include: _all 
> # xpack.security.audit.logfile.events.emit_request_body: true
> 
> ```
> 
> The last two lines are commented out for now but left there as placeholders to easily turn on in the future. These two settings generate large logs, but can be helpful to turn on temporarily when troubleshooting traffic request bodies.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2023, 7:18am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257/4 "2023-08-23T07:18:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
