In general,any process(including elasticsearch) will not get access to file system directly. Any process that want to perform a read or write operation on the file system will make api calls to kernel to get the work done.
You can try using auditbeat to monitor process activities where you can filter events specific to elasticsearch process.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.