# Security audits using elasticsearch

**URL:** <https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099>\
**Category:** Elasticsearch\
**Created:** [July 6, 2017, 12:47pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099 "2017-07-06T12:47:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [July 6, 2017, 12:47pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/1 "2017-07-06T12:47:26Z")

</div>

Can i use elasticsearch for security audits? For example I have 10 users accessing confidential datas everyday and I log this and index to elasticsearch. Will be be able to do random audits on these users,for example 2 different users and 2 different dates for every month. I was trying random score and function score

```auto
{
  "function_score": {
    "functions": [
      {
        "random_score": {}
      }
    ],
    "query": {
      "match_all": {}
    }
  }
}

```

but am not sure how to execute my needs.Please anyone have some idea please do let me know.

Thanks,

Raj

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [July 6, 2017, 1:17pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/2 "2017-07-06T13:17:52Z")

</div>

Hi,

Within X-Pack Security we have the following: [https://www.elastic.co/guide/en/x-pack/current/auditing.html](https://www.elastic.co/guide/en/x-pack/current/auditing.html)

If interested give the trial a go, [https://www.elastic.co/guide/en/x-pack/current/license-management.html](https://www.elastic.co/guide/en/x-pack/current/license-management.html)

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [July 6, 2017, 1:28pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/3 "2017-07-06T13:28:09Z")

</div>

Hi Jymit,

Thank you for the reply ,this not the audit for seeing who is accessing the elasticsearch cluster,its external data (which has info already who access it and which record he has accessed it ) ,I ingest that data into elasticsearch.

For examples, "Axcse" user accessed this record "aaaa" ,like this I have many documents different users accessing different records,and each logs I have it in json documents in elasticsearch ,so every month, I want to perform a audit on a random users and random dates.

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [July 13, 2017, 10:45am UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/4 "2017-07-13T10:45:56Z")

</div>

Please any one help me

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [July 14, 2017, 1:39pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/5 "2017-07-14T13:39:37Z")

</div>

Hi,

From a security POV, what are you looking to achieve here? Why the random user and random dates?

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [July 14, 2017, 1:57pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/6 "2017-07-14T13:57:00Z")

</div>

Hi,  
Thank you for the reply,

We receive logs from IBM cics to elasticsearch which has all the transaction info and personal numbers which are highly confidential datas and these confidential datas are viewed by certain users (authorised users) ,so we have to perform security audits on these users randomly on different dates every month ,since its not practically possible to see all the logs and why they have accessed those records,so thats why we want to audit two random users and two different dates ,all the logs whatever they accessed on that particular random dates.

Thanks in advance,  
Raj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2017, 1:57pm UTC](https://discuss.elastic.co/t/security-audits-using-elasticsearch/92099/7 "2017-08-11T13:57:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
