# Where audit logger methods are called

**URL:** <https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [August 2, 2020, 5:44pm UTC](https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470 "2020-08-02T17:44:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![houshmand1996](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houshmand1996/32/74233_2.png) [@houshmand1996](https://discuss.elastic.co/u/houshmand1996)\
**Post date:** [August 2, 2020, 5:44pm UTC](https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470/1 "2020-08-02T17:44:24Z")

</div>

where clientWrapper in kibana calls methods like this

```auto
public async update<T extends SavedObjectAttributes>(
   type: string,
   id: string,
   attributes: Partial<T>,
   options: SavedObjectsUpdateOptions = {}
 ) {
   await this.ensureAuthorized(type, 'update', options.namespace, {
     type,
     id,
     attributes,
     options,
   });

   return await this.baseClient.update(type, id, attributes, options);
 }

```

in this path : (x-pack / plugins / security / server / savedobject / SecureSavedObjectsClientWrapper )

in other words how and where user activities are logged in kibana ?

---

<div class="post-metadata">

**Author:** ![mikecote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikecote/32/58549_2.png) [@mikecote](https://discuss.elastic.co/u/mikecote)\
**Post date:** [August 19, 2020, 1:32pm UTC](https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470/2 "2020-08-19T13:32:49Z")

</div>

Hi @houshmand1996,

You can learn more about the Kibana audit logs here: [https://www.elastic.co/guide/en/kibana/current/xpack-security-audit-logging.html](https://www.elastic.co/guide/en/kibana/current/xpack-security-audit-logging.html). They are disabled by default and include steps to enable it.

---

<div class="post-metadata">

**Author:** ![houshmand1996](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houshmand1996/32/74233_2.png) [@houshmand1996](https://discuss.elastic.co/u/houshmand1996)\
**Post date:** [August 20, 2020, 11:39am UTC](https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470/3 "2020-08-20T11:39:41Z")

</div>

hi thanks for your response  
but i'm not looking for enabling audit logging what's i'm actually looking for is how this audit logging in security plugins works and how it logged every action that user made . i went through of codes each and every lines but i could not finds out about that .  
if you knowing anything please let me now .

---

<div class="post-metadata">

**Author:** ![mikecote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikecote/32/58549_2.png) [@mikecote](https://discuss.elastic.co/u/mikecote)\
**Post date:** [August 20, 2020, 12:46pm UTC](https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470/4 "2020-08-20T12:46:08Z")

</div>

This happens within the same file as the code snippet above but within the `ensureAuthorized` function. You can look for `this.auditLogger.savedObjectsAuthorizationSuccess` and `this.auditLogger.savedObjectsAuthorizationFailure` calls.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2020, 12:46pm UTC](https://discuss.elastic.co/t/where-audit-logger-methods-are-called/243470/5 "2020-09-17T12:46:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
