User management audit events in Elasticsearch

I can see in the audit logs on my linux box (/var/log...... ) when I create a user in Kibana or change a user. However this same log file does not show when I delete a user in Kibana. Does that event get logged to another log file or is it a setting I have to enable within Kibana?


Hi @landoncarlson85,

Hmm, is it ES audit logs or Kibana? I can't recall that Kibana was using audit logging for cases like this (though eventually it will).


These events related to the actions described above are in the ES audit logs.


Got it, then I'll move this topic to Elasticsearch so they can give you more details. In the meantime, this issue seems to be relevant.