# Tracking user activity in Appsearch UI through logs

**URL:** <https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [February 5, 2021, 11:16am UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373 "2021-02-05T11:16:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Subhasis\_Dash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subhasis_dash/32/68827_2.png) [@Subhasis\_Dash](https://discuss.elastic.co/u/Subhasis_Dash)\
**Post date:** [February 5, 2021, 11:16am UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/1 "2021-02-05T11:16:32Z")

</div>

Is there any way we can track user activities like

1. what they searched
2. what document they accessed  
after logging in to appsearch UI through logs or some other ways for audit.

Please let me know if any solution.

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [February 5, 2021, 12:12pm UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/2 "2021-02-05T12:12:02Z")

</div>

You can check at elasticsearch level, there is an index where all activities (search, results, clicks ...) are stored, something like this

```auto
.ent-search-app-search-analytics-ecs-ilm-logs-production-YYYY.MM.dd-00000x

```

---

<div class="post-metadata">

**Author:** ![Subhasis\_Dash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subhasis_dash/32/68827_2.png) [@Subhasis\_Dash](https://discuss.elastic.co/u/Subhasis_Dash)\
**Post date:** [February 10, 2021, 5:32am UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/3 "2021-02-10T05:32:54Z")

</div>

HI Ylasri, tried accessing that index but we only get lm\_account\_id in the above mentioned index not the user\_oid, is there any way to configure app-search so that the user\_oid will also be logged ?  
sample response below

```auto
 {
                "_index": ".ent-search-app-search-analytics-ecs-ilm-logs-production-2021.02.09-000001",
                "_type": "_doc",
                "_id": "IbqQhXcBk-1x-EvGC74V",
                "_score": 1.0,
                "_source": {
                    "@timestamp": "2021-02-09T06:52:20.884Z",
                    "agent": {
                        "id": "5a164c26-95e9-40d0-a193-601a771929e0",
                        "version": "7.6.0",
                        "type": "filebeat",
                        "ephemeral_id": "0f8b03ec-5471-4df4-a840-a77035f690d7",
                        "hostname": "33aab3e7aff8"
                    },
                    "labels": {
                        "index_date": "2021.02.09",
                        "engine_id": "602230fdc32e8a58371fadb8",
                        "lm_account_id": "60223043c32e8a722f8b8749"
                    },
                    "related": {
                        "ip": "172.18.0.1"
                    },
                    "log": {
                        "offset": 0,
                        "file": {
                            "path": "/var/log/enterprise-search/filebeat.log"
                        }
                    },
                    "event": {
                        "tags": [],
                        "dataset": "app-search-analytics",
                        "category": "app-search-analytics",
                        "action": "loco_moco_search",
                        "created": "2021-02-09T06:52:20Z",
                        "query_string": "",
                        "loco_moco_search_request_id": "d55092f4-fb47-456d-a08f-27b6e0aa5f77",
                        "document_ids": [
                            "park_saguaro",
                            "park_rocky-mountain"
                        ]
                    },
                    "ecs": {
                        "version": "1.5.0"
                    },
                    "input": {
                        "type": "log"
                    },
                    "host": {
                        "name": "33aab3e7aff8"
                    }
                }
            }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 10, 2021, 6:06am UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/4 "2021-02-10T06:06:09Z")

</div>

Hi @Subhasis_Dash

Perhaps I am missing something have you tried the [Analytics API](https://www.elastic.co/guide/en/app-search/current/analytics.html) it there to answer those questions.

---

<div class="post-metadata">

**Author:** ![SriAkash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sriakash/32/77423_2.png) [@SriAkash](https://discuss.elastic.co/u/SriAkash)\
**Post date:** [February 10, 2021, 3:32pm UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/5 "2021-02-10T15:32:28Z")

</div>

Hello @stephenb ,

Analytics API do returns the number of counts but we are mainly looking to capture which user has done the operation from appsearch GUI

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 10, 2021, 4:31pm UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/6 "2021-02-10T16:31:02Z")

</div>

Perhaps use the tags on the [Search](https://www.elastic.co/guide/en/app-search/current/tags.html) and [Click](https://www.elastic.co/guide/en/app-search/current/clickthrough.html) API have you tried to put a user identifier into the tags?

BTW I checked with the App Search team and they said you could absolutely use this method.

Give it a try and let us know.

---

<div class="post-metadata">

**Author:** ![SriAkash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sriakash/32/77423_2.png) [@SriAkash](https://discuss.elastic.co/u/SriAkash)\
**Post date:** [February 11, 2021, 9:56am UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/7 "2021-02-11T09:56:39Z")

</div>

Putting user identifier into tags and then using search and click API helps if we are making query via APIs. I am looking to track the user activities if they actually login to APP Search GUI interface and search/view any document. Is there anyway if I can also add tags in this scenario?

---

<div class="post-metadata">

**Author:** ![Subhasis\_Dash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subhasis_dash/32/68827_2.png) [@Subhasis\_Dash](https://discuss.elastic.co/u/Subhasis_Dash)\
**Post date:** [February 11, 2021, 10:35am UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/8 "2021-02-11T10:35:04Z")

</div>

Hi @ylasri @stephenb ,  
To explain more about this scenario:

1. users named **"testUser","testUser1","testUser2"** are created in appsearch UI
2. **testUser** logs into **appsearch**  **UI**
3. testUser uses **Query tester** in appsearch UI to search using "test" keyword **(Not the search api)** and gets some result
4. testUser clicks on one of the document
5. now **testUser2** follows the same steps as "testUser" but clicks on another document

Now in **analytics** we can see "test" keyword is searched 2 times and click count is 2 also we see what documents are clicked,  
However what we donot see is which document is clicked by testUser2 and which by testUser  
And as both users in this scenario are using **Appsearch UI** portal not the **apis** we are not sure how to send **tags**.

If the scenario is clear, our question Is there a way to capture/configure or see these kind of user activites that were performed using appsearch UI?

```auto
.ent-search-app-search-analytics-ecs-ilm-logs-production-YYYY.MM.dd-00000x

```

this index seems to have some details but only with account\_id, which is same for all users. Is it possible to capture UserId too?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 11, 2021, 3:48pm UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/9 "2021-02-11T15:48:04Z")

</div>

Hi @Subhasis_Dash

Apologies I did not understand you are trying to use the app Search UI for this, using it it as the search interface.

It is not really the the intended use for the App Search UI it is meant to be and Admin interface so I don't think it supports what you are looking to do.

I have passed this on to product to take a look.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2021, 3:48pm UTC](https://discuss.elastic.co/t/tracking-user-activity-in-appsearch-ui-through-logs/263373/10 "2021-03-11T15:48:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
