# Massive /var/log/audit logging

**URL:** <https://discuss.elastic.co/t/massive-var-log-audit-logging/56366>\
**Category:** Elasticsearch\
**Created:** [July 26, 2016, 8:35am UTC](https://discuss.elastic.co/t/massive-var-log-audit-logging/56366 "2016-07-26T08:35:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![memelet](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@memelet](https://discuss.elastic.co/u/memelet)\
**Post date:** [July 26, 2016, 8:35am UTC](https://discuss.elastic.co/t/massive-var-log-audit-logging/56366/1 "2016-07-26T08:35:08Z")

</div>

We configure our nodes with basic Ubuntu CIS ([https://benchmarks.cisecurity.org/tools2/linux/CIS\_Ubuntu\_14.04\_LTS\_Server\_Benchmark\_v1.0.0.pdf](https://benchmarks.cisecurity.org/tools2/linux/CIS_Ubuntu_14.04_LTS_Server_Benchmark_v1.0.0.pdf)).

On our elasticsearch data nodes this results in an amazing number of audit logs. So much that it fills our 24G log volumes in just a few hours. The logs look like

```
type=SYSCALL msg=audit(1469521785.213:19745470): arch=c000003e syscall=87 success=yes exit=0 a0=7f5030092480 a1=7f4d30c92530 a2=7f5030092480 a3=7f5039f3ebc1 items=2 ppid=1 pid=17326 auid=1003 uid=20000 gid=20000 euid=20000 suid=20000 fsuid=20000 egid=20000 sgid=20000 fsgid=20000 tty=(none) ses=2 comm="java" exe="/usr/lib/jvm/java-8-oracle/jre/bin/java" key="delete"
type=CWD msg=audit(1469521785.213:19745470): cwd="/usr/share/elasticsearch"
type=PATH msg=audit(1469521785.213:19745470): item=0 name="/data/es/staging/nodes/0/indices/connect-mtconnectdataitems-201607/2/index/" inode=7080182 dev=ca:50 mode=040755 ouid=20000 ogid=20000 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1469521785.213:19745470): item=1 name="/data/es/staging/nodes/0/indices/connect-mtconnectdataitems-201607/2/index/_4ol2.fnm" inode=7079803 dev=ca:50 mode=0100644 ouid=20000 ogid=20000 rdev=00:00 nametype=DELETE
type=SYSCALL msg=audit(1469521785.213:19745471): arch=c000003e syscall=87 success=yes exit=0 a0=7f5030092480 a1=7f4d30c92530 a2=7f5030092480 a3=7f5039f3ebc1 items=2 ppid=1 pid=17326 auid=1003 uid=20000 gid=20000 euid=20000 suid=20000 fsuid=20000 egid=20000 sgid=20000 fsgid=20000 tty=(none) ses=2 comm="java" exe="/usr/lib/jvm/java-8-oracle/jre/bin/java" key="delete"
type=CWD msg=audit(1469521785.213:19745471): cwd="/usr/share/elasticsearch"
type=PATH msg=audit(1469521785.213:19745471): item=0 name="/data/es/staging/nodes/0/indices/connect-mtconnectdataitems-201607/2/index/" inode=7080182 dev=ca:50 mode=040755 ouid=20000 ogid=20000 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1469521785.213:19745471): item=1 name="/data/es/staging/nodes/0/indices/connect-mtconnectdataitems-201607/2/index/_4ol2.nvd" inode=7078132 dev=ca:50 mode=0100644 ouid=20000 ogid=20000 rdev=00:00 nametype=DELETE

```

Is this normal. Should we expect ES to be creating and deleting files so rapidly?

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [July 26, 2016, 9:31am UTC](https://discuss.elastic.co/t/massive-var-log-audit-logging/56366/2 "2016-07-26T09:31:50Z")

</div>

This seems not as an Elasticsearch-related question - but yes, Elasticsearch rapidly creates and deletes tens of thousands of files.

You are running Ubuntu "CIS", which I identify as "Center for Internet Security" (whatever that means), so I guess you are running a Linux kernel with fully enabled audit logs, which is quite uncommon.

You can switch kernel auditing temporarily off by

```auto
/usr/sbin/auditctl -e 0

```

or you can switch it off permanently by configuring your Linux kernel boot line b ythe parameter `audit=0`, see `cat /proc/cmdline`

Other configuration about managing auditing configuration and logs is available in `/etc/audit/auditd.conf`

---

<div class="post-metadata">

**Author:** ![memelet](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@memelet](https://discuss.elastic.co/u/memelet)\
**Post date:** [July 26, 2016, 9:41am UTC](https://discuss.elastic.co/t/massive-var-log-audit-logging/56366/3 "2016-07-26T09:41:45Z")

</div>

Thanks @jprante. I don't really want to disable the directories that logstash writes to via auditd.rules.

I really wanted to know if generating 1GB/hour of logs like the above we might indicate that we have some misconfiguration that is causing ES to thrash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:32pm UTC](https://discuss.elastic.co/t/massive-var-log-audit-logging/56366/4 "2017-07-05T22:32:58Z")

</div>


