# Logging for each query requested in elasticsearch cluster

**URL:** <https://discuss.elastic.co/t/logging-for-each-query-requested-in-elasticsearch-cluster/83834>\
**Category:** Elasticsearch\
**Created:** [April 27, 2017, 9:51am UTC](https://discuss.elastic.co/t/logging-for-each-query-requested-in-elasticsearch-cluster/83834 "2017-04-27T09:51:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ultimate.duwal](https://avatars.discourse-cdn.com/v4/letter/u/2acd7d/32.png) [@ultimate.duwal](https://discuss.elastic.co/u/ultimate.duwal)\
**Post date:** [April 27, 2017, 9:51am UTC](https://discuss.elastic.co/t/logging-for-each-query-requested-in-elasticsearch-cluster/83834/1 "2017-04-27T09:51:50Z")

</div>

I was wondering if it is possible to add logs of **each query being hit to elasticsearch**  **_regardless_** of its success or failure.  
If possible certain information of user querying it to the log.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 5, 2017, 12:37pm UTC](https://discuss.elastic.co/t/logging-for-each-query-requested-in-elasticsearch-cluster/83834/2 "2017-05-05T12:37:47Z")

</div>

With the slowlog you can potentially log every single request but it may dramatically slow down your service.  
About "user", well if you are using x-pack, then you can use audit logging may be? Unsure if all queries are logged though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2017, 12:48pm UTC](https://discuss.elastic.co/t/logging-for-each-query-requested-in-elasticsearch-cluster/83834/3 "2017-06-02T12:48:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
