# Secure specific indices from users manually updating documents

**URL:** <https://discuss.elastic.co/t/secure-specific-indices-from-users-manually-updating-documents/312042>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 12, 2022, 10:54pm UTC](https://discuss.elastic.co/t/secure-specific-indices-from-users-manually-updating-documents/312042 "2022-08-12T22:54:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [August 12, 2022, 10:54pm UTC](https://discuss.elastic.co/t/secure-specific-indices-from-users-manually-updating-documents/312042/1 "2022-08-12T22:54:33Z")

</div>

Hi,

Elasticsearch Version: 7.16.1  
ECK version: 1.6.1

We use ELK to push audit logs from one of our applications and we'd like to know if there is a way to know if any HUMAN user manually updated any documents in that specific index. We push logs from S3 bucket to a specific index using logstash s3 plugin and no one should manually update/delete the index documents. These audit logs are super important and should not be updated manually by anyone. (FYI: technically any admin in our team has access to root credentials so anyone can be a culprit 😜 )

If that is not possible maybe we there is a way to log all queries that are either deleting/updating documents in that specific index? if yes, what would I be looking for in the ES audit logs?

- I looked at slow query logs and they are not very helpful as they don't show any usernames
- I don't have much knowledge on audit logs

Thank you

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 13, 2022, 1:41am UTC](https://discuss.elastic.co/t/secure-specific-indices-from-users-manually-updating-documents/312042/2 "2022-08-13T01:41:13Z")

</div>

Hi @Rakesh_B

Elasticsearch has **strong** RBAC... down to the index + document and field (for commercial subscription) so that is all you need to do 🙂

Index level RBAC is available with the Basic / Free Subscription.

Oh details.... 🙂

So I just help secure a large scale production cluster... and some ways ... Writers get to write... Analysts / everyone else get to read 🙂

1. We created the publisher role / API for all automated ingesting ... so your logstash should only use the `logstash_writer` role... you can create a user or and API Key. Per [Here](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-basic)

2. Then your users only get read privileges on the indices / documents... it can be as simple as that ... and very secure!

This RBAC is set at the cluster / index level... I am thinking I would start there.

The UI makes it pretty easy to define roles these days..

 ![Screen Shot 2022-08-12 at 6.55.19 PM](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eab64a4cfc5d247dc676364dabeba6cf7305fa29.jpeg)

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 15, 2022, 1:54am UTC](https://discuss.elastic.co/t/secure-specific-indices-from-users-manually-updating-documents/312042/3 "2022-08-15T01:54:49Z")

</div>

> [@Rakesh\_B](#):
>
> We push logs from S3 bucket to a specific index using logstash s3 plugin and no one should manually update/delete the index documents.

I guess what you want here is a "true append-only" index which it is not possible today.

> log all queries that are either deleting/updating documents in that specific index?

This is doable with audit logs. I suggested you follow our documentation [Enable audit logging | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html)  
Please do note that the audit logging feature is platinum licensed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2022, 1:55am UTC](https://discuss.elastic.co/t/secure-specific-indices-from-users-manually-updating-documents/312042/4 "2022-09-12T01:55:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
