# Xpack.security.audit.outputs: \[ index, logfile \] in 7.x?

**URL:** <https://discuss.elastic.co/t/xpack-security-audit-outputs-index-logfile-in-7-x/214336>\
**Category:** Elasticsearch\
**Created:** [January 9, 2020, 2:39am UTC](https://discuss.elastic.co/t/xpack-security-audit-outputs-index-logfile-in-7-x/214336 "2020-01-09T02:39:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![retr0s](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/retr0s/32/60523_2.png) [@retr0s](https://discuss.elastic.co/u/retr0s)\
**Post date:** [January 9, 2020, 2:39am UTC](https://discuss.elastic.co/t/xpack-security-audit-outputs-index-logfile-in-7-x/214336/1 "2020-01-09T02:39:44Z")

</div>

Hello,

Uptil 6.2 the security audits could be sent to an ES index by setting this line elasticsearch.yml file

```
xpack.security.audit.outputs: [index, logfile]

https://www.elastic.co/guide/en/x-pack/current/auditing.html#audit-log-settings

```

In 7.x the audit logs can be only written to clustername\_audit.json or console.

My question is how can the audit logs be sent to an ES index, just like 6.2? Is there any such option anymore?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2020, 2:39am UTC](https://discuss.elastic.co/t/xpack-security-audit-outputs-index-logfile-in-7-x/214336/2 "2020-02-06T02:39:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
