# Log users and query in audit log

**URL:** <https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446>\
**Category:** Elasticsearch\
**Created:** [May 18, 2018, 9:22am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446 "2018-05-18T09:22:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ol3k](https://avatars.discourse-cdn.com/v4/letter/o/919ad9/32.png) [@ol3k](https://discuss.elastic.co/u/ol3k)\
**Post date:** [May 18, 2018, 9:22am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/1 "2018-05-18T09:22:00Z")

</div>

Hi,

we set up a new ELK Cluster and enabled audit logging:

Is there any possibility to log the username and all queries done by the user?  
In the audit log we just see successful / failed logins etc. but never any queries.

Thanks.

Regards  
Carsten

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [May 18, 2018, 10:17am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/2 "2018-05-18T10:17:10Z")

</div>

In regards to audit logging. logfile output. Vanilla out of the box implementation v6.2.4

```auto
[transport] [access_granted]	origin_type=[rest], origin_address=[127.0.0.1], principal=[elastic], roles=[superuser], action=[cluster:monitor/nodes/info], request=[NodesInfoRequest]

```

We get the `principal` whom is the user at the time of request.

```auto
 [rest] [authentication_failed]|origin_address=[127.0.0.1], principal=[jakamo], uri=[/_xpack/security/_authenticate]

```

Principal `jakamo` here is for a failed login into kibana.

```auto
[transport] [access_granted]|origin_type=[rest], origin_address=[127.0.0.1], principal=[elastic], roles=[superuser], action=[indices:data/read/get], indices=[squid], request=[GetRequest]
[transport] [access_granted]|origin_type=[rest], origin_address=[127.0.0.1], principal=[elastic], roles=[superuser], action=[indices:data/read/get[s]], indices=[squid], request=[GetRequest]|

```

The query here was a GET req to the squid index.

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [May 20, 2018, 12:51pm UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/3 "2018-05-20T12:51:13Z")

</div>

Hi @ol3k,

Complementing @JKhondhu's answer, you can log the request body by setting `xpack.security.audit.logfile.events.emit_request_body: true`. More info here:  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.2/auditing-settings.html#event-audit-settings](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/auditing-settings.html#event-audit-settings)

---

<div class="post-metadata">

**Author:** ![ol3k](https://avatars.discourse-cdn.com/v4/letter/o/919ad9/32.png) [@ol3k](https://discuss.elastic.co/u/ol3k)\
**Post date:** [May 29, 2018, 11:31am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/4 "2018-05-29T11:31:01Z")

</div>

Hi @JKhondhu, Hi @Albert_Zaharovits

i think that this should be configured in my elasticsearch.yml

```
xpack.security.audit.enabled: true
xpack.security.audit.outputs: [index,logfile]
xpack.security.audit.logfile.events.emit_request_body: true

```

We also see the request made to the indices, but we don't get the Searchphrase / query.

```
[2018-05-29T13:16:49,994] [transport] [access_granted] origin_type=[rest], origin_address=[127.0.0.1], principal=[niehuepe], roles=[superuser], action=[indices:data/read/get], indices=[.kibana], request=[GetRequest]
[2018-05-29T13:16:50,003] [transport] [access_granted] origin_type=[rest], origin_address=[127.0.0.1], principal=[niehuepe], roles=[superuser], action=[indices:data/read/get[s]], indices=[.kibana], request=[GetRequest]

```

Is there something missing for the logstash-\* index?

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [May 29, 2018, 12:01pm UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/5 "2018-05-29T12:01:51Z")

</div>

Hi @ol3k,

Not all events contain the `request_body` attribute. In this case, `access_granted` events do not. Look at the `authentication_*` events (if you have enabled them). The reason is that the REST request content is gone by the time actions are authorized (`access_granted` events).  
Arguably the docs for this are in development, [https://www.elastic.co/guide/en/x-pack/current/auditing.html#audit-event-attributes](https://www.elastic.co/guide/en/x-pack/current/auditing.html#audit-event-attributes), but they are accurate for you present enquiry.

---

<div class="post-metadata">

**Author:** ![ol3k](https://avatars.discourse-cdn.com/v4/letter/o/919ad9/32.png) [@ol3k](https://discuss.elastic.co/u/ol3k)\
**Post date:** [May 30, 2018, 11:06am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/6 "2018-05-30T11:06:42Z")

</div>

Hi @Albert_Zaharovits

yes, thanks!  
Indeed it's logging the request now with "authentication\_success" included events.

We are logging it into index and file:

```
[2018-05-30T12:50:14,978] [rest] [authentication_success] principal=[niehuepe], realm=[default_native], uri=[/_msearch], params=[{}], request_body=[{"index":["logstash-*"],"ignore_unavailable":true,"preference":1527675455811}
        {"version":true,"size":500,"sort":[{"@timestamp":{"order":"desc","unmapped_type":"boolean"}}],"_source":{"excludes":[]},"aggs":{"2":{"date_histogram":{"field":"@timestamp","interval":"30s","time_zone":"Europe/Berlin","min_doc_count":1}}},"stored_fields":["*"],"script_fields":{},"docvalue_fields":["@timestamp","received_at"],"query":{"bool":{"must":[{"query_string":{"query":"test123","analyze_wildcard":true,"default_field":"*"}},{"match_phrase":{"event_type":{"query":"authentication_success"}}},{"range":{"@timestamp":{"gte":1527676514877,"lte":1527677414877,"format":"epoch_millis"}}}],"filter":[],"should":[],"must_not":[]}},"highlight":{"pre_tags":["@kibana-highlighted-field@"],"post_tags":["@/kibana-highlighted-field@"],"fields":{"*":{}},"fragment_size":2147483647}}
        ]

```

> {"query\_string":{"query":"test123","analyze\_wildcard":true,"default\_field":"\*"}}

In index the request\_body is not searchable and aggregatable. Perhaps it's struggling with the Linebreak?!

Is there any chance to search this field within Kibana?

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [June 1, 2018, 10:13am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/7 "2018-06-01T10:13:59Z")

</div>

Hi @ol3k,

Unfortunately you have have hit a pain point about index auditing, namely indexing the request content.

Right now there is no way for the user to change the mapping of the audit security index. In other words, you cannot change how fields of audit events are searched (i.e. datatype,`text`, `keyword` , analyzers ...). Because request bodies are diverse, there is no mapping that can accommodate all request formats, so the `request body` field is unsearchable (data type is `keyword` but `index` is false).  
So the answer for:

> Is there any chance to search this field within Kibana?

is no.

There is no easy solution for this problem. What we are actively working on, is to have an easy path, inside the stack, for users to define their own indices when indexing audit events.

At the present time `request_body` field should be treated as not machine readable.

---

<div class="post-metadata">

**Author:** ![ol3k](https://avatars.discourse-cdn.com/v4/letter/o/919ad9/32.png) [@ol3k](https://discuss.elastic.co/u/ol3k)\
**Post date:** [June 4, 2018, 5:49am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/8 "2018-06-04T05:49:31Z")

</div>

Hi @Albert_Zaharovits,  
hi @JKhondhu,

OK, thanks for your detailed answer.

Anyway thanks for your help in this thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2018, 5:49am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/9 "2018-07-02T05:49:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
