# Kibana Audit Log - Alerting Rule Deletion

**URL:** <https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645>\
**Category:** Kibana\
**Created:** [March 14, 2023, 9:59am UTC](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645 "2023-03-14T09:59:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wanch](https://avatars.discourse-cdn.com/v4/letter/w/ee59a6/32.png) [@wanch](https://discuss.elastic.co/u/wanch)\
**Post date:** [March 14, 2023, 9:59am UTC](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645/1 "2023-03-14T09:59:51Z")

</div>

Hi,

I have a question regarding Kibana's audit logging and the deletion of alerting rules.

Below is the audit logs I got for deleting an alerting rule in Kibana UI:

```auto
{
  "event": {
    "action": "http_request",
    "category": [
      "web"
    ],
    "outcome": "unknown"
  },
  "http": {
    "request": {
      "method": "delete"
    }
  },
  "url": {
    "domain": "10.0.41.111",
    "path": "/api/alerting/rule/95f95c80-c246-11ed-ba1f-9d1770043f8b",
    "port": 5601,
    "scheme": "https"
  },
  "user": {
    "name": "elastic",
    "roles": [
      "superuser"
    ]
  },
  "kibana": {
    "space_id": "default",
    "session_id": "0UIiCmiKybqcmf5iQ//4H9LLwItzejuaq871azMEwkQ="
  },
  "trace": {
    "id": "b638a8c1-9afd-4e7d-bf2e-7681f3d5e9ed"
  },
  "service": {
    "node": {
      "roles": [
        "background_tasks",
        "ui"
      ]
    }
  },
  "ecs": {
    "version": "8.4.0"
  },
  "@timestamp": "2023-03-14T05:00:10.427-04:00",
  "message": "User is requesting [/api/alerting/rule/95f95c80-c246-11ed-ba1f-9d1770043f8b] endpoint",
  "log": {
    "level": "INFO",
    "logger": "plugins.security.audit.ecs"
  },
  "process": {
    "pid": 1600759
  },
  "transaction": {
    "id": "c478044baa4c0347"
  }
}
{
  "event": {
    "action": "space_get",
    "category": [
      "database"
    ],
    "type": [
      "access"
    ],
    "outcome": "success"
  },
  "kibana": {
    "space_id": "default",
    "session_id": "0UIiCmiKybqcmf5iQ//4H9LLwItzejuaq871azMEwkQ=",
    "saved_object": {
      "type": "space",
      "id": "default"
    }
  },
  "user": {
    "name": "elastic",
    "roles": [
      "superuser"
    ]
  },
  "trace": {
    "id": "b638a8c1-9afd-4e7d-bf2e-7681f3d5e9ed"
  },
  "service": {
    "node": {
      "roles": [
        "background_tasks",
        "ui"
      ]
    }
  },
  "ecs": {
    "version": "8.4.0"
  },
  "@timestamp": "2023-03-14T05:00:10.437-04:00",
  "message": "User has accessed space [id=default]",
  "log": {
    "level": "INFO",
    "logger": "plugins.security.audit.ecs"
  },
  "process": {
    "pid": 1600759
  },
  "transaction": {
    "id": "c478044baa4c0347"
  }
}
{
  "event": {
    "action": "rule_delete",
    "category": [
      "database"
    ],
    "type": [
      "deletion"
    ],
    "outcome": "unknown"
  },
  "kibana": {
    "space_id": "default",
    "session_id": "0UIiCmiKybqcmf5iQ//4H9LLwItzejuaq871azMEwkQ=",
    "saved_object": {
      "type": "alert",
      "id": "95f95c80-c246-11ed-ba1f-9d1770043f8b"
    }
  },
  "user": {
    "name": "elastic",
    "roles": [
      "superuser"
    ]
  },
  "trace": {
    "id": "b638a8c1-9afd-4e7d-bf2e-7681f3d5e9ed"
  },
  "service": {
    "node": {
      "roles": [
        "background_tasks",
        "ui"
      ]
    }
  },
  "ecs": {
    "version": "8.4.0"
  },
  "@timestamp": "2023-03-14T05:00:10.465-04:00",
  "message": "User is deleting rule [id=95f95c80-c246-11ed-ba1f-9d1770043f8b]",
  "log": {
    "level": "INFO",
    "logger": "plugins.security.audit.ecs"
  },
  "process": {
    "pid": 1600759
  },
  "transaction": {
    "id": "c478044baa4c0347"
  }
}

```

From the audit log, it shows that the user _elastic_ has deleted the rule with id 95f95c80-c246-11ed-ba1f-9d1770043f8b. However, is there a way to map back this rule id to the human-readable name, eg. "Check CPU Load" so that the auditor can confirm that the rule "Check CPU Load" is deleted by the user _elastic_?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2023, 10:00am UTC](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645/2 "2023-04-11T10:00:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
