# Request for enhancement: Messages like "Authentication using apikey failed" need source IP address

**URL:** <https://discuss.elastic.co/t/request-for-enhancement-messages-like-authentication-using-apikey-failed-need-source-ip-address/383629>\
**Category:** Elasticsearch\
**Created:** [November 24, 2025, 6:42pm UTC](https://discuss.elastic.co/t/request-for-enhancement-messages-like-authentication-using-apikey-failed-need-source-ip-address/383629 "2025-11-24T18:42:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [November 24, 2025, 6:42pm UTC](https://discuss.elastic.co/t/request-for-enhancement-messages-like-authentication-using-apikey-failed-need-source-ip-address/383629/1 "2025-11-24T18:42:28Z")

</div>

It’s difficult to find where these bad API keys are coming from. The only suggestion is to enable audit, which is overkill and uses a lot of resources logging 99% of the audit events that are good.

If the x\_forwarded\_for and source\_ip fields could be added, tracking down bad requests would be much easier with much less data logged.
