# Tracking down who created Dashboards and Visualizations

**URL:** <https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475>\
**Category:** Kibana\
**Created:** [October 8, 2020, 3:34pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475 "2020-10-08T15:34:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaw](https://avatars.discourse-cdn.com/v4/letter/s/5e9695/32.png) [@Shaw](https://discuss.elastic.co/u/Shaw)\
**Post date:** [October 8, 2020, 3:34pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/1 "2020-10-08T15:34:12Z")

</div>

Is there any ways to track down who created a dashboard and visualizaions? I do not see any options or places to indicate who created it, who was last person to modify it, and when. It will be very helpful when audit tons of the dashbords and visualizations. Please advise.

Thank you,  
Shaw

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 8, 2020, 4:04pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/2 "2020-10-08T16:04:35Z")

</div>

Looked in the logs for the event when creating a visualization and I don't see who created it.

```auto
{
   "type":"response",
   "@timestamp":"2020-10-08T15:53:12Z",
   "tags":[
      
   ],
   "pid":7,
   "method":"post",
   "statusCode":200,
   "req":{
      "url":"/api/saved_objects/visualization?overwrite=true",
      "method":"post",
      "headers":{
         "host":"localhost:5601",
         "connection":"keep-alive",
         "content-length":"881",
         "kbn-version":"7.6.0",
         "user-agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36",
         "content-type":"application/json",
         "accept":"*/*",
         "origin":"http://localhost:5601",
         "sec-fetch-site":"same-origin",
         "sec-fetch-mode":"cors",
         "sec-fetch-dest":"empty",
         "referer":"http://localhost:5601/app/kibana",
         "accept-encoding":"gzip, deflate, br",
         "accept-language":"en-US,en;q=0.9"
      },
      "remoteAddress":"172.19.0.1",
      "userAgent":"172.19.0.1",
      "referer":"http://localhost:5601/app/kibana"
   },
   "res":{
      "statusCode":200,
      "responseTime":996,
      "contentLength":9
   },
   "message":"POST /api/saved_objects/visualization?overwrite=true 200 996ms - 9.0B"
}

```

Looked in the Kibana index and also in the exported JSON and can see updated time but not by whom.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c99433e6c2d185e4109e34c34f0e105522dfde98.png)

So my answer is no unless the reason I am not seeing it is due to not having security enabled and only the default user. You can try to replicate what I did above on your side to see if it does show a user ID.

---

<div class="post-metadata">

**Author:** ![Shaw](https://avatars.discourse-cdn.com/v4/letter/s/5e9695/32.png) [@Shaw](https://discuss.elastic.co/u/Shaw)\
**Post date:** [October 8, 2020, 4:40pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/4 "2020-10-08T16:40:25Z")

</div>

Thank you @aaron-nimocks for your prompt response. I do see the "updated\_at" info, that is good and now I need to figure out how I can enable security feature to present the username in the doc, any ideas?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 8, 2020, 4:45pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/5 "2020-10-08T16:45:58Z")

</div>

@Shaw [enable audit logging](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html)

---

<div class="post-metadata">

**Author:** ![Shaw](https://avatars.discourse-cdn.com/v4/letter/s/5e9695/32.png) [@Shaw](https://discuss.elastic.co/u/Shaw)\
**Post date:** [October 8, 2020, 5:04pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/6 "2020-10-08T17:04:51Z")

</div>

Great, thank you! I will check with my DevOps person for the enable audit logging status. Do you have a sample screenshot what kind of user info/format will be presented in the query result for dashboard/visualization?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 8, 2020, 5:08pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/7 "2020-10-08T17:08:35Z")

</div>

I was on a call with your DevOps person when you asked. 🙂

No I don't have a screenshot but [here are the fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-event-types.html) it should capture.

`When audit logging is enabled, security events are persisted to a dedicated <clustername>_audit.json file on the host’s file system (on each node).`

First I would try to locate that file and see the contents.

---

<div class="post-metadata">

**Author:** ![Shaw](https://avatars.discourse-cdn.com/v4/letter/s/5e9695/32.png) [@Shaw](https://discuss.elastic.co/u/Shaw)\
**Post date:** [October 8, 2020, 5:20pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/8 "2020-10-08T17:20:32Z")

</div>

Hah~ Cool, this is very helpful, thank! I will check with my DevOps further.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2020, 5:20pm UTC](https://discuss.elastic.co/t/tracking-down-who-created-dashboards-and-visualizations/251475/9 "2020-11-05T17:20:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
