# Log users and query in audit log

**URL:** <https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446>\
**Category:** Elasticsearch\
**Created:** [May 18, 2018, 9:22am UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446 "2018-05-18T09:22:00Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [May 29, 2018, 12:01pm UTC](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446/5 "2018-05-29T12:01:51Z")

</div>

Hi @ol3k,

Not all events contain the `request_body` attribute. In this case, `access_granted` events do not. Look at the `authentication_*` events (if you have enabled them). The reason is that the REST request content is gone by the time actions are authorized (`access_granted` events).  
Arguably the docs for this are in development, [https://www.elastic.co/guide/en/x-pack/current/auditing.html#audit-event-attributes](https://www.elastic.co/guide/en/x-pack/current/auditing.html#audit-event-attributes), but they are accurate for you present enquiry.

---

_[View the full topic](https://discuss.elastic.co/t/log-users-and-query-in-audit-log/132446)._
