# Start with audit log

**URL:** <https://discuss.elastic.co/t/start-with-audit-log/375139>\
**Category:** Elastic Search\
**Tags:** docker\
**Created:** [February 27, 2025, 8:57am UTC](https://discuss.elastic.co/t/start-with-audit-log/375139 "2025-02-27T08:57:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![felixwong](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Post date:** [February 27, 2025, 8:57am UTC](https://discuss.elastic.co/t/start-with-audit-log/375139/1 "2025-02-27T08:57:00Z")

</div>

HI ,  
I am new to ealsticsearch , and installed docker version . I want to start with log pattern match development for example audit log for user login . Can anyone share how do I start , which tools is good for it . Thank for you help in advance . My audit log patter is similar below example

TID: [-1234] [2025-02-03 00:00:24,328] [a5fe5708-458c-480d-9d97-2e45d581e2b0] INFO {AUDIT\_LOG} - Initiator : xxxnamexxx | Action : LoginStepSuccess | Target : ApplicationAuthenticationFramework | Data : { "ContextIdentifier" : "6e01a5d2-4bd4-4b10-a974-03f6b087fc7d","AuthenticatedUser" : "xxxnamexxx","AuthenticatedUserTenantDomain" : "carbon.super","ServiceProviderName" : "myportal\_web","RequestType" : "cas","RelyingParty" : "myportal\_web","AuthenticatedIdP" : "ADFS4\_PROD","UserStoreDomain" : "null","User Agent" : "null","RemoteAddress" : "null" } | Result : Success  
TID: [-1234] [2025-02-03 00:00:24,360] [a5fe5708-458c-480d-9d97-2e45d581e2b0] INFO {AUDIT\_LOG} - Initiator : xxxnamexxx | Action : Login | Target : ApplicationAuthenticationFramework | Data : { "ContextIdentifier" : "6e01a5d2-4bd4-4b10-a974-03f6b087fc7d","AuthenticatedUser" : "xxxnamexxx","AuthenticatedUserTenantDomain" : "null","ServiceProviderName" : "myportal\_web","RequestType" : "cas","RelyingParty" : "myportal\_web","AuthenticatedIdPs" : "eyJ0eXAiOiJKV1QiLCAiYWxnIjoibm9uZSJ9.eyJpc3MiOiJ3c28yIiwiZXhwIjoxNzM4NTEyMDI0MzMxMzAwMCwiaWF0IjoxNzM4NTEyMDI0MzMxLCJpZHBzIjpbeyJpZHAiOiJBREZTNF9QUk9EIiwiYXV0aGVudGljYXRvciI6IlNBTUxTU09BdXRoZW50aWNhdG9yIn1dfQ==.","UserStoreDomain" : "null","User Agent" : "null","RemoteAddress" : "null" } | Result : Success

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2025, 8:57am UTC](https://discuss.elastic.co/t/start-with-audit-log/375139/2 "2025-03-27T08:57:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
