# Stack access audit

**URL:** <https://discuss.elastic.co/t/stack-access-audit/191817>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Tags:** elastic-stack-security\
**Created:** [July 23, 2019, 12:58pm UTC](https://discuss.elastic.co/t/stack-access-audit/191817 "2019-07-23T12:58:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [July 23, 2019, 12:58pm UTC](https://discuss.elastic.co/t/stack-access-audit/191817/1 "2019-07-23T12:58:06Z")

</div>

I am wondering what's the best way to go about implementing Access logging for individual indexes. Specifically, is there a log that can show which user access information per index or indices?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [July 29, 2019, 3:18pm UTC](https://discuss.elastic.co/t/stack-access-audit/191817/2 "2019-07-29T15:18:02Z")

</div>

ES has a security audit module, with 2 ways of shipping data:

- (deprecated) over transport protocol ... this should work in ECE for now
- to file ... currently that is shipped to the Logging and Metrics cluster (so you have to ensure the cluster is appropriately sized for the volume) and there is no easy way of separating access to this from other cluster logs

Longer term we are working on being able to ship different log types to different clusters (including external ones)

---

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [July 31, 2019, 4:40am UTC](https://discuss.elastic.co/t/stack-access-audit/191817/3 "2019-07-31T04:40:12Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 4:40am UTC](https://discuss.elastic.co/t/stack-access-audit/191817/4 "2019-08-14T04:40:20Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
