# Tracking the execution of Scroll API in Elasticsearch

**URL:** <https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630>\
**Category:** Elasticsearch\
**Created:** [May 16, 2024, 1:09pm UTC](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630 "2024-05-16T13:09:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 16, 2024, 1:09pm UTC](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630/1 "2024-05-16T13:09:49Z")

</div>

Hi everyone,

I'm currently working with Elasticsearch and I'm interested in tracking the execution of the Scroll API. Specifically, I want to audit the use of the Scroll API to keep track of when it is executed and by which user.

Is it possible to achieve this through Elasticsearch or Kibana auditing? If so, could anyone provide guidance or share their experiences on how to set this up?

Alternatively, if there are better methods or tools for achieving this kind of tracking, I would appreciate any suggestions.

Thank you!

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [May 17, 2024, 7:19pm UTC](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630/2 "2024-05-17T19:19:45Z")

</div>

Hi @yago82 !

You could use [Audit Logging](https://www.elastic.co/guide/en/elasticsearch/reference/current/enable-audit-logging.html) in Elasticsearch.

Take into account that audit logging is only available in specific [subscriptions](https://www.elastic.co/subscriptions) - please check that out.

Using a proxy in front of Elasticsearch would make it possible to access that information from the headers and path of the Elasticsearch requests.

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 20, 2024, 7:30am UTC](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630/3 "2024-05-20T07:30:40Z")

</div>

> [@yago82](#):
>
> Hi everyone,
> 
> I'm currently working with Elasticsearch and I'm interested in tracking the execution of the Scroll API. Specifically, I want to audit the use of the Scroll API to keep track of when it is executed and by which user.
> 
> Is it possible to achieve this through Elasticsearch or Kibana auditing? If so, could anyone provide guidance or share their experiences on how to set this up?
> 
> Alternatively, if there are better methods or tools for achieving this kind of tracking, I would appreciate any suggestions.
> 
> Thank you!

Hi Carlos,

First of all, thank you for the information.

In order to avoid overloading the cluster by enabling all audit settings, could you please guide me on the specific settings needed to track the use of the Scroll API?

Any detailed instructions or experiences you can share would be greatly appreciated.

Thank you!

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [May 20, 2024, 8:17am UTC](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630/4 "2024-05-20T08:17:34Z")

</div>

Given your use case, I'd say that you need to [track access granted operations](https://www.elastic.co/guide/en/elasticsearch/reference/current/auditing-settings.html#event-audit-settings) to the scroll API (see [audit events for REST event types](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-event-types.html#audit-event-types)):

- `xpack.security.audit.logfile.events.include: access_granted`

You could also add [ignore policies](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-log-ignore-policy.html), and [ignore actions](https://www.elastic.co/guide/en/elasticsearch/reference/current/auditing-settings.html#audit-event-ignore-policies) you're not interested on (which will be all actions except for the scroll API):

- `xpack.security.audit.logfile.events.ignore_filters.<policy_name>.actions`

I'd recommend to setup a audit logging on a test cluster and experiment with these options until you get the audit log that you need for the action you're interested in.

Hope that helps!
