# Audit All user actions

**URL:** <https://forum.opensearch.org/t/audit-all-user-actions/2053>\
**Category:** Security\
**Created:** [December 25, 2019, 10:30am UTC](https://forum.opensearch.org/t/audit-all-user-actions/2053 "2019-12-25T10:30:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![waeshalaby](https://avatars.discourse-cdn.com/v4/letter/w/c68b51/32.png) [@waeshalaby](https://forum.opensearch.org/u/waeshalaby)\
**Post date:** [December 25, 2019, 10:30am UTC](https://forum.opensearch.org/t/audit-all-user-actions/2053/1 "2019-12-25T10:30:56Z")

</div>

We are wondering if we can log all ‘KQL’ for all users with granted permissions to query these indices as we try with the default installation to discover all audit actions  
but only the default tracked events are:

- Failed login
- Successful login
- Missing privileges to run a certain request
- Granted privileges to run a certain request
- SSL/TLS error when Elasticsearch was contacted but there was no certificate or the provided certificate was incorrect
- Attempt to alter the configuration of the internal security module without required privileges
- Attempt to interact with Elasticsearch without security headers

doesn’t contain user successful search queries.

---

<div class="post-metadata">

**Author:** ![mato](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@mato](https://forum.opensearch.org/u/mato)\
**Post date:** [April 15, 2020, 1:37pm UTC](https://forum.opensearch.org/t/audit-all-user-actions/2053/2 "2020-04-15T13:37:52Z")

</div>

Hi,

opendistro guys, please answer

thanks

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [May 5, 2021, 5:16pm UTC](https://forum.opensearch.org/t/audit-all-user-actions/2053/3 "2021-05-05T17:16:04Z")

</div>

Hi @waeshalaby Did you get this working? the [docs](https://opendistro.github.io/for-elasticsearch-docs/docs/security/audit-logs/field-reference/) seems to cover most of what you are looking for
