# Vault Logging using Elasticsearch

**URL:** <https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring, docker\
**Created:** [November 24, 2023, 5:17am UTC](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897 "2023-11-24T05:17:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![VijayIQA](https://avatars.discourse-cdn.com/v4/letter/v/e19b73/32.png) [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Post date:** [November 24, 2023, 5:17am UTC](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897/1 "2023-11-24T05:17:42Z")

</div>

Hi team,

As per elastic [docs](https://docs.elastic.co/en/integrations/hashicorp_vault) at

` vault audit enable socket address=${ELASTIC_AGENT_IP}:9007 socket_type=tcp`

In the place of ELASTIC\_AGENT\_IP I placed Elasticsearch IP and port as 9200 in this case getting an error as

```auto
* audit backend failed test message: event.(SocketSink).Process: error writing to socket: 2 errors occurred:
        * event.(SocketSink).write: connection error: event.(SocketSink).connect: error connecting to "tcp" address "x.x.x.x:9200": dial tcp x.x.x.x:9200: i/o timeout
        * event.(SocketSink).reconnect: error connecting: event.(SocketSink).connect: error connecting to "tcp" address "x.x.x.x:9200": dial tcp x.x.x.x:9200: i/o timeout

```

here, Elasticsearch running on https with x-pack security username and password then, how to pass this command.  
` vault audit enable socket address=${ELASTIC_AGENT_IP}:9007 socket_type=tcp`

with certification verify false and username password.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2023, 5:18am UTC](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897/2 "2023-12-22T05:18:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
