How Do I Enable the Audit Log Function for an Elasticsearch Cluster?
Currently, CSS Elasticsearch clusters of the 7.6.2 and later versions support the audit log function. By default, this function is disabled.
![](https://support.huaweicloud.com/intl/en-us/css_faq/public_sys-resources/note_3.0-en-us.png)
The cluster must be a security cluster.
- Log in to the CSS management console.
- In the navigation pane, choose Clusters. The cluster list is displayed.
- Click the name of the target cluster to go to the cluster details page.
- In the navigation pane on the left, choose Parameter Configurations. Click Edit, expand the Customize parameter, and click Add.
Set Key to opendistro_security.audit.type and Value to internal_elasticsearch.
Figure 1 Configuring a custom parameter - After the modification is complete, click Submit.In the displayed Submit Configuration dialog box, select the box indicating "I understand that the modification will take effect after the cluster is restarted." and click Yes.
If the Status is Succeeded in the parameter modification list, the modification has been saved.
- Return to the cluster list and choose More > Restart in the Operation column to restart the cluster and make the modification take effect.
- After the cluster is restarted, click Access Kibana in the Operation column. On the displayed page, enter the username and password. The Dev Tools page is displayed.
- In the Console page, run the GET _cat/indices?v command. If there are indexes related to .*audit* index, the audit log function is enabled.
Parameter Configuration FAQs
- How Do I Set the search.max_buckets Parameter for an Elasticsearch Cluster?
- Can I Modify the TLS Algorithm of an Elasticsearch Cluster?
- How Do I Enable the Audit Log Function for an Elasticsearch Cluster?
- How Do I Query the Index Size on OBS After the Freezing of Indexes for a CSS Cluster?
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbotmore