# Is there a way to monitor changes to roles and username / passwords for builtin or created users

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [August 18, 2023, 7:56pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129 "2023-08-18T19:56:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![txmrlevine](https://avatars.discourse-cdn.com/v4/letter/t/5daacb/32.png) [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Post date:** [August 18, 2023, 7:56pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/1 "2023-08-18T19:56:15Z")

</div>

Our Security team is looking for a way for them to use Carbon Black to monitor changes to users (add/ delete) , password changes for these adhoc users or built in users. we were looking for a file on disk. The only info I found on line is to create or change passwords not where they are stored so they can be monitored. I understand there is a secure index called .security ( in the database) but is this kept in a file? We cannot seem to find that file. with the other indicies.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 18, 2023, 8:45pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/2 "2023-08-18T20:45:45Z")

</div>

The proper method would to be use audit logging.

Where Elasticsearch actually persists the security data is opaque to users... So that is not a good approach.

Data is stored in indices, which is stored in shards which are then made up of segments. Segments can change for a number of reasons...not related to data be written... So even if you knew the segment again that would not be a reliable approach..

---

<div class="post-metadata">

**Author:** ![txmrlevine](https://avatars.discourse-cdn.com/v4/letter/t/5daacb/32.png) [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Post date:** [August 18, 2023, 9:27pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/3 "2023-08-18T21:27:21Z")

</div>

we are already trapping the audit logs on the hosts to ELK stack. are you talking about that or something else.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 18, 2023, 9:49pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/4 "2023-08-18T21:49:50Z")

</div>

Edited for clarity

Yes elasticsearch audit logs... There are some settings to make sure your auditing the events you want. But yeah elasticsearch audit logs that's the correct way

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 19, 2023, 3:38am UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/5 "2023-08-19T03:38:33Z")

</div>

> [@txmrlevine](#):
>
> we are already trapping the audit logs on the hosts to ELK stack. are you talking about that or something else.

If I'm not wrong Stephen is mentioning the Audit Logs of Elasticsearch, which needs to be [enabled](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html) and also needs a Paid License.

Those logs will have information about [changed to built-in users](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-event-types.html) for example.

---

<div class="post-metadata">

**Author:** ![txmrlevine](https://avatars.discourse-cdn.com/v4/letter/t/5daacb/32.png) [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Post date:** [August 19, 2023, 4:20pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/6 "2023-08-19T16:20:10Z")

</div>

One more quick question – would that be on the master node and what would I be looking for in the Audit logs, what type strings?

![~WRD000.jpg](https://us1.discourse-cdn.com/elastic/original/3X/5/2/52d5f1c08649212fe6768d2cacdcf8df711810d9.jpeg)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 20, 2023, 12:25am UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/7 "2023-08-20T00:25:21Z")

</div>

Per the docs... Every node

> When audit logging is enabled, security events are persisted to a dedicated \_audit.json file on the host’s file system, on every cluster node. For more information, see Logfile audit output.

The events actually are categorized as `event.actions` ... The enumeration is [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-event-types.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2023, 12:26am UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129/8 "2023-09-17T00:26:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
