# Audit logging enabled but not able to see index level entries

**URL:** <https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433>\
**Category:** Security\
**Tags:** configure\
**Created:** [May 17, 2024, 9:03am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433 "2024-05-17T09:03:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mangesh.mathe.9](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mangesh.mathe.9](https://forum.opensearch.org/u/mangesh.mathe.9)\
**Post date:** [May 17, 2024, 9:03am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/1 "2024-05-17T09:03:38Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
Opensearch 2.13.0

**Describe the issue** :  
I have enabled audit logging on OpenSearch and I can see my audit index created with name “audit-logs”  
I have performed some CRUD operations on one of my cluster index. I don’t see entries for that operations in the audit index.  
As far as I know elasticsearch have that capabilities to see each entry related to CRUD operations that we do on any Index in the audit log index.  
Could you please help me track index operation entries in the audit index.

**Configuration** :  
settings that I’ve added in opensearch.yml:

plugins.security.audit.type: internal\_opensearch  
plugins.security.audit.config.log\_request\_body: true  
plugins.security.audit.config.disabled\_rest\_categories: NONE  
plugins.security.audit.config.disabled\_transport\_categories: NONE  
plugins.security.audit.config.enable\_rest: true  
plugins.security.audit.config.enable\_transport: true  
plugins.security.audit.config.index: “audit-logs”  
plugins.security.audit.config.ignore\_users: “kibanaserver, logstash”  
plugins.security.audit.config.resolve\_indices: true  
plugins.security.audit.config.resolve\_bulk\_requests: true

**Relevant Logs or Screenshots** :

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/7/7e904f7de17bac794fe2715cad5ba1d7c2cbe301.png)

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [May 17, 2024, 3:42pm UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/2 "2024-05-17T15:42:38Z")

</div>

Hi @mangesh.mathe.9

> [@mangesh.mathe.9](#):
>
> I don’t see entries for that operations in the audit index.

What user did you use? Could you send an example of your CRUD operation?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [May 17, 2024, 3:57pm UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/3 "2024-05-17T15:57:50Z")

</div>

Could you please also send a screenshot of your audit log configurations in the OpenSearch Dashboards? To do this, click on **Security → Audit logs** and scroll to **General settings**.

---

<div class="post-metadata">

**Author:** ![mangesh.mathe.9](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mangesh.mathe.9](https://forum.opensearch.org/u/mangesh.mathe.9)\
**Post date:** [May 21, 2024, 6:18am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/4 "2024-05-21T06:18:32Z")

</div>

I have used admin user and performing crud operations like inserting , updating and delete the index document.

CRUD operations that I performed,  
\*/  
POST opensearch\_dashboards\_sample\_data\_flights/\_doc/  
{  
“FlightNum”: “AB123”,  
“Dest”: “SFO”,  
“Origin”: “JFK”,  
“AvgTicketPrice”: 500,  
“timestamp”: “2024-05-13T12:00:00Z”  
}  
POST opensearch\_dashboards\_sample\_data\_flights/\_update/gEe2hY8BigLP3L3Hf14W  
{  
“doc”: {  
“AvgTicketPrice”: 550  
}  
}  
GET opensearch\_dashboards\_sample\_data\_flights/\_search

DELETE opensearch\_dashboards\_sample\_data\_flights/\_doc/gEe2hY8BigLP3L3Hf14W  
/\*

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/5/589c75ce9b60b9404b8dd03218915a6c05d6cce3.png)

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [May 21, 2024, 10:25am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/5 "2024-05-21T10:25:28Z")

</div>

Hi @mangesh.mathe.9 ,

Disabled REST categories are different in the config file and in the UI. Did you restart your cluster after making changes to the opensearch.yml file?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [May 21, 2024, 10:31am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/6 "2024-05-21T10:31:59Z")

</div>

Please also check if the audit configuration in the `opensearch.yml` file is the same on every node in the cluster.

---

<div class="post-metadata">

**Author:** ![mangesh.mathe.9](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mangesh.mathe.9](https://forum.opensearch.org/u/mangesh.mathe.9)\
**Post date:** [May 21, 2024, 10:44am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/7 "2024-05-21T10:44:19Z")

</div>

yes I have restarted the opensearch.service and opensearch-dashboard .service

---

<div class="post-metadata">

**Author:** ![mangesh.mathe.9](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mangesh.mathe.9](https://forum.opensearch.org/u/mangesh.mathe.9)\
**Post date:** [May 21, 2024, 10:45am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/8 "2024-05-21T10:45:46Z")

</div>

we have implemented opensearch with only one node cluster. We are exploring the capabilities of opensearch.

---

<div class="post-metadata">

**Author:** ![mangesh.mathe.9](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mangesh.mathe.9](https://forum.opensearch.org/u/mangesh.mathe.9)\
**Post date:** [May 22, 2024, 10:39am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/9 "2024-05-22T10:39:02Z")

</div>

anything that you want to add here to resolve my audit log issue?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [May 22, 2024, 11:31am UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/10 "2024-05-22T11:31:23Z")

</div>

How did you install OpenSearch?

To fix it, please try removing GRANTED\_PRIVILEGES in the UI Settings:

 ![Screenshot 2024-05-22 at 12.28.04](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/1/1f46de85e01f76b0a93c61e19d6595423170a032.jpeg)

---

<div class="post-metadata">

**Author:** ![mangesh.mathe.9](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mangesh.mathe.9](https://forum.opensearch.org/u/mangesh.mathe.9)\
**Post date:** [May 22, 2024, 12:27pm UTC](https://forum.opensearch.org/t/audit-logging-enabled-but-not-able-to-see-index-level-entries/19433/11 "2024-05-22T12:27:30Z")

</div>

Thank you so much. I have removed this settings from UI and did restarted the OpenSearch which solved this issue. I can see my CRUD operations now in the audit log index.
