# Store Elasticsearch Indices in a revision/audit-proof way

**URL:** <https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668>\
**Category:** Elasticsearch\
**Created:** [May 22, 2014, 8:36am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668 "2014-05-22T08:36:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![german23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/german23/32/11052_2.png) [@german23](https://discuss.elastic.co/u/german23)\
**Post date:** [May 22, 2014, 8:36am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/1 "2014-05-22T08:36:20Z")

</div>

Hey guys,

in order to meet the german laws for logging, i got the order to store the  
elasticsearch indices in a revision/audit-proof way(Indices cannot be  
edited/changed after the storage).

Are there any best practices or tips for doing such a thing?(maybe any  
plugins?)

Thanks for your feedback.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 22, 2014, 8:40am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/2 "2014-05-22T08:40:19Z")

</div>

You can set indexes to readonly -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Is that what you're after?

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 22 May 2014 18:36, horst knete [baduncle23@hotmail.de](mailto:baduncle23@hotmail.de) wrote:

> Hey guys,
> 
> in order to meet the german laws for logging, i got the order to store the  
> elasticsearch indices in a revision/audit-proof way(Indices cannot be  
> edited/changed after the storage).
> 
> Are there any best practices or tips for doing such a thing?(maybe any  
> plugins?)
> 
> Thanks for your feedback.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624atDMQa6BePHCm7ZAqXDxXp3yHoAjrzos91QF\_0jWphsw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624atDMQa6BePHCm7ZAqXDxXp3yHoAjrzos91QF_0jWphsw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![german23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/german23/32/11052_2.png) [@german23](https://discuss.elastic.co/u/german23)\
**Post date:** [May 22, 2014, 8:46am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/3 "2014-05-22T08:46:39Z")

</div>

Yeah it looks like that this would do the job, thanks for response

Am Donnerstag, 22. Mai 2014 10:40:19 UTC+2 schrieb Mark Walkom:

> You can set indexes to readonly -  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-update-settings.html)  
> Is that what you're after?
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 22 May 2014 18:36, horst knete \<[badun...@hotmail.de](mailto:badun...@hotmail.de) \<javascript:\>\>wrote:
> 
> > Hey guys,
> > 
> > in order to meet the german laws for logging, i got the order to store  
> > the elasticsearch indices in a revision/audit-proof way(Indices cannot be  
> > edited/changed after the storage).
> > 
> > Are there any best practices or tips for doing such a thing?(maybe any  
> > plugins?)
> > 
> > Thanks for your feedback.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e2776ff1-4dde-4e96-85b0-f19cd9ad6c9b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e2776ff1-4dde-4e96-85b0-f19cd9ad6c9b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 22, 2014, 8:49am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/4 "2014-05-22T08:49:04Z")

</div>

Keep us up to date with your project, I'm sure there would be interested  
from others on a similar setup.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 22 May 2014 18:46, horst knete [baduncle23@hotmail.de](mailto:baduncle23@hotmail.de) wrote:

> Yeah it looks like that this would do the job, thanks for response
> 
> Am Donnerstag, 22. Mai 2014 10:40:19 UTC+2 schrieb Mark Walkom:
> 
> > You can set indexes to readonly - [http://www.elasticsearch](http://www.elasticsearch).  
> > org/guide/en/elasticsearch/reference/current/indices-update-settings.html  
> > Is that what you're after?
> > 
> > Regards,  
> > Mark Walkom
> > 
> > Infrastructure Engineer  
> > Campaign Monitor  
> > email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com)  
> > web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> > 
> > On 22 May 2014 18:36, horst knete [badun...@hotmail.de](mailto:badun...@hotmail.de) wrote:
> > 
> > > Hey guys,
> > > 
> > > in order to meet the german laws for logging, i got the order to store  
> > > the elasticsearch indices in a revision/audit-proof way(Indices cannot be  
> > > edited/changed after the storage).
> > > 
> > > Are there any best practices or tips for doing such a thing?(maybe any  
> > > plugins?)
> > > 
> > > Thanks for your feedback.
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%  
> > > [40googlegroups.com](http://40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/e2776ff1-4dde-4e96-85b0-f19cd9ad6c9b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e2776ff1-4dde-4e96-85b0-f19cd9ad6c9b%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/e2776ff1-4dde-4e96-85b0-f19cd9ad6c9b%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/e2776ff1-4dde-4e96-85b0-f19cd9ad6c9b%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624Yy6uXAaDU\_4bxyvKmezA7T5zB73sdF6V\_HRPabLkb9UA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624Yy6uXAaDU_4bxyvKmezA7T5zB73sdF6V_HRPabLkb9UA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [May 22, 2014, 8:55am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/5 "2014-05-22T08:55:44Z")

</div>

You have to add a facility to your middleware that can trace all authorized  
operations to your index (access, read, write, modify, delete) and you must  
write this to an append-only logfile with timestamps.

If there is interest I could write such a plugin (assuming it can run in a  
trusted environment regarding authorization tokens) but I think best place  
is in a middleware (where an ES client runs in a broader application  
context e.g. transaction awareness).

Jörg

On Thu, May 22, 2014 at 10:36 AM, horst knete [baduncle23@hotmail.de](mailto:baduncle23@hotmail.de) wrote:

> Hey guys,
> 
> in order to meet the german laws for logging, i got the order to store the  
> elasticsearch indices in a revision/audit-proof way(Indices cannot be  
> edited/changed after the storage).
> 
> Are there any best practices or tips for doing such a thing?(maybe any  
> plugins?)
> 
> Thanks for your feedback.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoG7JxZW%3D\_VqLxW01BUcuP8BA2j\_MeiyLuZ-b4uTQmj3SQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoG7JxZW%3D_VqLxW01BUcuP8BA2j_MeiyLuZ-b4uTQmj3SQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![german23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/german23/32/11052_2.png) [@german23](https://discuss.elastic.co/u/german23)\
**Post date:** [May 22, 2014, 9:12am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/6 "2014-05-22T09:12:42Z")

</div>

Hi Jörg,

thanks for your offer.

I will contact you if there´s a need for such an plugin in our company.

Also i will keep you up to date if there´s breaking changes in our project.

Am Donnerstag, 22. Mai 2014 10:55:44 UTC+2 schrieb Jörg Prante:

> You have to add a facility to your middleware that can trace all  
> authorized operations to your index (access, read, write, modify, delete)  
> and you must write this to an append-only logfile with timestamps.
> 
> If there is interest I could write such a plugin (assuming it can run in a  
> trusted environment regarding authorization tokens) but I think best place  
> is in a middleware (where an ES client runs in a broader application  
> context e.g. transaction awareness).
> 
> Jörg
> 
> On Thu, May 22, 2014 at 10:36 AM, horst knete \<[badun...@hotmail.de](mailto:badun...@hotmail.de)\<javascript:\>
> 
> > wrote:
> 
> > Hey guys,
> > 
> > in order to meet the german laws for logging, i got the order to store  
> > the elasticsearch indices in a revision/audit-proof way(Indices cannot be  
> > edited/changed after the storage).
> > 
> > Are there any best practices or tips for doing such a thing?(maybe any  
> > plugins?)
> > 
> > Thanks for your feedback.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ed95d3f8-9266-4ee4-a1a4-d3764b1150a4%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4f2187bc-8d8e-4c3a-ae02-8eed30f3a175%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4f2187bc-8d8e-4c3a-ae02-8eed30f3a175%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:27am UTC](https://discuss.elastic.co/t/store-elasticsearch-indices-in-a-revision-audit-proof-way/17668/7 "2017-07-06T01:27:43Z")

</div>


