Skip to main content
Version: 5.2

Configuring the Search Anywhere Framework Audit Log

The audit log records security events in Search Anywhere Framework: authentication attempts, REST API and transport-layer requests, privilege checks, and reads or changes to data selected for compliance monitoring.

Search Anywhere Framework uses the OpenSearch Security audit mechanism. Events are generated on Search Anywhere Framework nodes and sent to the storage configured in opensearch.yml. The Search Anywhere Framework interface lets you enable auditing and change its dynamic parameters.

Journal audit

Please note

Enable only the required categories and attributes. Detailed auditing, especially logging successful requests, document contents, and _bulk operations, increases cluster load and storage usage.

Preparing the Storage​

Before configuring the audit log through the UI, set the audit storage type in opensearch.yml on every Search Anywhere Framework node. Use internal_opensearch to store events in the current cluster:

plugins.security.audit.type: internal_opensearch

After the initial opensearch.yml change, restart the nodes using the standard procedure for your Search Anywhere Framework installation.

systemctl restart opensearch

You can change the remaining parameters through the UI.

With internal_opensearch, events are written to an index in the current cluster. If the index name is not overridden, Search Anywhere Framework creates daily indices in the internal_audit-YYYY.MM format. You can configure the name and rotation period separately:

plugins.security.audit.config.index: "'internal_audit-'YYYY.MM"

Opening the Settings​

To open the Audit Log settings in the interface:

  1. Open Main Menu
  2. Go to Settings - Security Settings
  3. In the Security section, select Audit Log
  4. In the Audit Logging block, enable Enable Audit Logging if it is disabled
  5. Configure the General Settings and Compliance Parameters blocks using the Edit buttons
  6. Select Save. The Cancel button closes the form without saving changes

Alternatively:

  1. Open Main Menu
  2. Go to Settings - Dev Tools
  3. Run GET _plugins/_security/api/audit
  4. Change the settings with PUT or PATCH requests. For example:
PUT /_plugins/_security/api/audit/config
{
"enabled": true,
"audit": {
"ignore_users": [],
"ignore_requests": [],
"disabled_rest_categories": [
"AUTHENTICATED",
"GRANTED_PRIVILEGES"
],
"disabled_transport_categories": [
"AUTHENTICATED",
"GRANTED_PRIVILEGES"
],
"log_request_body": false,
"resolve_indices": false,
"resolve_bulk_requests": false,
"exclude_sensitive_headers": true,
"enable_transport": false,
"enable_rest": true
},
"compliance": {
"enabled": true,
"write_log_diffs": false,
"read_watched_fields": {},
"read_ignore_users": [],
"write_watched_indices": [],
"write_ignore_users": [],
"read_metadata_only": true,
"write_metadata_only": true,
"external_config": false,
"internal_config": true
}
}
Please note

The user must have permissions to manage Search Anywhere Framework security settings.

General Settings​

This section describes the General Settings parameters of the audit log.

General settings

Layer Settings​

UI parameterKeyPurpose
REST Layeraudit:enable_restLogs external HTTP requests to the REST API
Disabled REST Categoriesaudit:disabled_rest_categoriesExcludes selected REST event categories
Transport Layeraudit:enable_transportLogs internal transport requests between Search Anywhere Framework components and nodes
Disabled Transport Categoriesaudit:disabled_transport_categoriesExcludes selected transport event categories

Main audit categories include FAILED_LOGIN, AUTHENTICATED, MISSING_PRIVILEGES, GRANTED_PRIVILEGES, SSL_EXCEPTION, OPENDISTRO_SECURITY_INDEX_ATTEMPT, BAD_HEADERS, CLUSTER_SETTINGS_CHANGED, and INDEX_SETTINGS_CHANGED.

Attribute Settings​

UI parameterKeyPurpose and recommendations
Bulk Requestsaudit:resolve_bulk_requestsSplits a _bulk request into separate document-operation events
Request Bodyaudit:log_request_bodyAdds the request body to the event; it may contain sensitive data
Resolve Indicesaudit:resolve_indicesAdds original and resolved index names, including aliases and patterns
Sensitive Headersaudit:exclude_sensitive_headersExcludes confidential headers such as Authorization; keep enabled

Ignore Settings​

UI parameterKeyPurpose
Ignored Usersaudit:ignore_usersDoes not create events for the specified users
Ignored Requestsaudit:ignore_requestsDoes not create events for matching transport actions or REST API paths; patterns are supported
info

Do not exclude administrator accounts without separate justification. After changing exclusions, verify that the operations under investigation continue to be logged.

Compliance Parameters​

Compliance mode supplements regular auditing with security-configuration change events and read or write monitoring for selected data.

Compliance parameters

Mode and Configuration​

UI parameterKeyPurpose
Enable Compliance Loggingcompliance:enabledEnables compliance parameter processing
Log Internal Configurationcompliance:internal_configLogs changes to internal Security configuration
Log External Configurationcompliance:external_configLogs changes to external security configuration

Read Monitoring​

UI parameterKeyPurpose
Read Metadata Onlycompliance:read_metadata_onlyLogs access metadata without document contents
Ignored Userscompliance:read_ignore_usersExcludes specified users from read auditing
Watched Fieldscompliance:read_watched_fieldsLimits read monitoring to specified indices and fields

The Watched Fields field accepts a JSON object where the key is an index or index pattern and the value is a list of fields or field patterns:

{
"logs*": ["message"],
"users": ["id", "email", "profile.*"]
}

Write Monitoring​

UI parameterKeyPurpose
Write Metadata Onlycompliance:write_metadata_onlyLogs only write-operation metadata without document contents
Write Log Diffscompliance:write_log_diffsStores document changes instead of the full state
Ignored Userscompliance:write_ignore_usersExcludes specified users from write auditing
Watched Indicescompliance:write_watched_indicesLimits write auditing to specified indices or patterns
TaskRecommended parameters
Login and access-error monitoringKeep FAILED_LOGIN, AUTHENTICATED, MISSING_PRIVILEGES, SSL_EXCEPTION, and BAD_HEADERS; disable request-body logging
Access-denial investigationEnable REST and transport layers and index resolution; do not exclude MISSING_PRIVILEGES
Administrative-change monitoringEnable Enable Compliance Logging and Log Internal Configuration; do not exclude administrators
Critical-data access monitoringConfigure Watched Fields and Watched Indices; keep metadata-only modes enabled
Full successful-operation tracingDo not exclude GRANTED_PRIVILEGES; assess performance, retention, and audit-index volume in advance

Verifying the Configuration​

After saving the settings:

  1. Perform a safe test action that matches an enabled category, such as a successful request or an intentionally rejected request from a test user
  2. Make sure that a new record appears in the selected storage
  3. Check audit_category, audit_request_layer, the user, the path or transport action, and affected indices
  4. Make sure that the request body and sensitive headers are absent when their logging is disabled
  5. Make sure that user and request exclusions do not hide required events

For internal_opensearch, analyze records with Search Anywhere Framework search and visualization tools using the audit index. Event fields are described in Audit Log Field Descriptions.

Verification examples:

  1. Run the following request
GET _cat/shards

The equivalent request in the console:

curl -XGET -ku <User> "https://localhost:9200/_cat/shards"
  1. Go to Main Menu - Basic - Search and run the following query
source internal_audit-*
| search audit_rest_request_path.keyword = "/_cat/shards"
  1. Find the event for this request
{
"_index": "internal_audit-2026.08",
"_type": "internal:internal_audit-*:",
"_id": "1veJR6ABznHokKDdW0t_",
"_score": 0,
"_source": {
"audit_cluster_name": "saf-cluster",
"audit_rest_request_params": {
"pretty": "true"
},
"audit_node_name": "saf-node-00",
"audit_request_initiating_user": "admin",
"audit_rest_request_method": "GET",
"audit_category": "AUTHENTICATED",
"audit_request_origin": "REST",
"audit_node_id": "USQ4yKPDRY-sNSb2B6QXTA",
"audit_request_layer": "REST",
"audit_rest_request_path": "/_cat/shards",
"@timestamp": "2026-08-28T08:42:59.326+00:00",
"audit_request_effective_user_is_admin": false,
"audit_format_version": 4,
"audit_request_remote_address": "127.0.0.1",
"audit_node_host_address": "172.17.0.2",
"audit_rest_request_headers": {
"content-length": [
"0"
],
"x-forwarded-host": [
"localhost:5601"
],
"x-forwarded-proto": [
"https"
],
"x-opensearch-product-origin": [
"opensearch-dashboards"
],
"Connection": [
"keep-alive"
],
"x-forwarded-port": [
"39620"
],
"x-opaque-id": [
"7289f351-9229-47b6-a3aa-40d2cb020eb2"
],
"content-type": [
"application/json"
],
"Host": [
"localhost:9200"
],
"x-forwarded-for": [
"172.17.0.1"
],
"user-agent": [
"opensearch-js/2.13.0 (linux 5.15.167.4-microsoft-standard-WSL2-x64; Node.js v22.22.1)"
]
},
"audit_request_effective_user": "admin",
"audit_node_host_name": "172.17.0.2"
}
}

Alternatively, verify a Search Anywhere Framework job request:

GET _core/job_scheduler/jobs

The equivalent request in the console:

curl -XGET -ku <User> "https://localhost:9200/_core/job_scheduler/jobs"

Run the following query in Main Menu - Basic - Search:

source internal_audit-*
| search audit_rest_request_path.keyword = "/_core/job_scheduler/jobs"
{
"_index": "internal_audit-2026.08",
"_type": "internal:internal_audit-*:",
"_id": "cPeOR6ABznHokKDdFExS",
"_score": 0,
"_source": {
"audit_cluster_name": "saf-cluster",
"audit_rest_request_params": {
"pretty": "true"
},
"audit_node_name": "saf-node-00",
"audit_request_initiating_user": "admin",
"audit_rest_request_method": "GET",
"audit_category": "AUTHENTICATED",
"audit_request_origin": "REST",
"audit_node_id": "USQ4yKPDRY-sNSb2B6QXTA",
"audit_request_layer": "REST",
"audit_rest_request_path": "/_core/job_scheduler/jobs",
"@timestamp": "2026-08-28T08:48:08.785+00:00",
"audit_request_effective_user_is_admin": false,
"audit_format_version": 4,
"audit_request_remote_address": "127.0.0.1",
"audit_node_host_address": "172.17.0.2",
"audit_rest_request_headers": {
"content-length": [
"0"
],
"x-forwarded-host": [
"localhost:5601"
],
"x-forwarded-proto": [
"https"
],
"x-opensearch-product-origin": [
"opensearch-dashboards"
],
"Connection": [
"keep-alive"
],
"x-forwarded-port": [
"54324"
],
"x-opaque-id": [
"7ce0a945-ab53-481f-ac80-c4431132d55a"
],
"content-type": [
"application/json"
],
"Host": [
"localhost:9200"
],
"x-forwarded-for": [
"172.17.0.1"
],
"user-agent": [
"opensearch-js/2.13.0 (linux 5.15.167.4-microsoft-standard-WSL2-x64; Node.js v22.22.1)"
]
},
"audit_request_effective_user": "admin",
"audit_node_host_name": "172.17.0.2"
}
}

Audit Log Field Descriptions​

General Fields​

The following attributes are recorded for all event categories, regardless of the layer.

Field nameDescription
audit_format_versionAudit log message format.
audit_categoryAudit log category. Possible values: FAILED_LOGIN, MISSING_PRIVILEGES, BAD_HEADERS, SSL_EXCEPTION, OPENDISTRO_SECURITY_INDEX_ATTEMPT, AUTHENTICATED, GRANTED_PRIVILEGES, CLUSTER_SETTINGS_CHANGED, and INDEX_SETTINGS_CHANGED.
audit_node_idID of the node that generated the event.
audit_node_nameName of the node that generated the event.
audit_node_host_addressHost address of the node.
audit_node_host_nameHost name of the node.
audit_request_layerLayer that generated the event: TRANSPORT or REST.
audit_request_originLayer from which the event originated: TRANSPORT or REST.
audit_request_effective_user_is_admintrue if the request was sent with an administrative TLS certificate; otherwise, false.

REST FAILED_LOGIN Fields​

The following attributes are recorded for failed REST login events.

Field nameDescription
audit_request_effective_userUser for whom authentication failed.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_rest_request_pathREST endpoint URI.
audit_rest_request_paramsHTTP request parameters, if present.
audit_rest_request_headersHTTP headers, if present.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_rest_request_methodHTTP request method.

REST SSL_EXCEPTION Fields​

The following attributes are recorded for REST SSL exception events.

Field nameDescription
audit_request_exception_stacktraceSSL exception stack trace.

REST BAD_HEADERS Fields​

The following attributes are recorded for REST events with invalid headers.

Field nameDescription
audit_rest_request_pathREST endpoint URI.
audit_rest_request_paramsHTTP request parameters, if present.
audit_rest_request_headersHTTP headers, if present.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.

Transport FAILED_LOGIN Fields​

The following attributes are recorded for transport failed-login events.

Field nameDescription
audit_trace_task_idRequest ID.
audit_transport_headersRequest headers, if present.
audit_request_effective_userUser for whom authentication failed.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_transport_request_typeRequest type, for example, IndexRequest.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_trace_indicesIndex names included in the request. May contain wildcards, date patterns, and aliases. Recorded only when resolve_indices is true.
audit_trace_resolved_indicesResolved index names affected by the request. Recorded only when resolve_indices is true.
audit_trace_doc_typesDocument types affected by the request. Recorded only when resolve_indices is true.

Transport AUTHENTICATED Fields​

The following attributes are recorded for transport successful-authentication events.

Field nameDescription
audit_trace_task_idRequest ID.
audit_transport_headersRequest headers, if present.
audit_request_effective_userUser for whom authentication succeeded.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_transport_request_typeRequest type, for example, IndexRequest.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_trace_indicesIndex names included in the request. May contain wildcards, date patterns, and aliases. Recorded only when resolve_indices is true.
audit_trace_resolved_indicesResolved index names affected by the request. Recorded only when resolve_indices is true.
audit_trace_doc_typesDocument types affected by the request. Recorded only when resolve_indices is true.

Transport MISSING_PRIVILEGES Fields​

The following attributes are recorded for transport events with missing privileges.

Field nameDescription
audit_trace_task_idRequest ID.
audit_trace_task_parent_idParent request ID, if present.
audit_transport_headersRequest headers, if present.
audit_request_effective_userUser for whom authentication failed.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_transport_request_typeRequest type, for example, IndexRequest.
audit_request_privilegeRequired request privilege, for example, indices:data/read/search.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_trace_indicesIndex names included in the request. May contain wildcards, date patterns, and aliases. Recorded only when resolve_indices is true.
audit_trace_resolved_indicesResolved index names affected by the request. Recorded only when resolve_indices is true.
audit_trace_doc_typesDocument types affected by the request. Recorded only when resolve_indices is true.

Transport GRANTED_PRIVILEGES Fields​

The following attributes are recorded for transport events with granted privileges.

Field nameDescription
audit_trace_task_idRequest ID.
audit_trace_task_parent_idParent request ID, if present.
audit_transport_headersRequest headers, if present.
audit_request_effective_userUser for whom authentication succeeded.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_transport_request_typeRequest type, for example, IndexRequest.
audit_request_privilegeRequired request privilege, for example, indices:data/read/search.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_trace_indicesIndex names included in the request. May contain wildcards, date patterns, and aliases. Recorded only when resolve_indices is true.
audit_trace_resolved_indicesResolved index names affected by the request. Recorded only when resolve_indices is true.
audit_trace_doc_typesDocument types affected by the request. Recorded only when resolve_indices is true.

Transport SSL_EXCEPTION Fields​

The following attributes are recorded for transport SSL exception events.

Field nameDescription
audit_request_exception_stacktraceSSL exception stack trace.

Transport BAD_HEADERS Fields​

The following attributes are recorded for transport events with invalid headers.

Field nameDescription
audit_trace_task_idRequest ID.
audit_trace_task_parent_idParent request ID, if present.
audit_transport_headersRequest headers, if present.
audit_request_effective_userUser for whom authentication failed.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_transport_request_typeRequest type, for example, IndexRequest.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_trace_indicesIndex names included in the request. May contain wildcards, date patterns, and aliases. Recorded only when resolve_indices is true.
audit_trace_resolved_indicesResolved index names affected by the request. Recorded only when resolve_indices is true.
audit_trace_doc_typesDocument types affected by the request. Recorded only when resolve_indices is true.

Transport OPENDISTRO_SECURITY_INDEX_ATTEMPT Fields​

The following attributes are recorded when a request attempts to access the security index.

Field nameDescription
audit_trace_task_idRequest ID.
audit_transport_headersRequest headers, if present.
audit_request_effective_userUser for whom authentication failed.
audit_request_initiating_userUser that sent the request. Recorded only when different from the current user.
audit_transport_request_typeRequest type, for example, IndexRequest.
audit_request_bodyHTTP request body, if present and request-body logging is enabled.
audit_trace_indicesIndex names included in the request. May contain wildcards, date patterns, and aliases. Recorded only when resolve_indices is true.
audit_trace_resolved_indicesResolved index names affected by the request. Recorded only when resolve_indices is true.
audit_trace_doc_typesDocument types affected by the request. Recorded only when resolve_indices is true.

Transport CLUSTER_SETTINGS_CHANGED Fields​

The following attributes are recorded when cluster settings change.

Field nameDescription
audit_request_effective_userUser who changed the settings.
audit_transport_request_typeRequest type, for example, ClusterUpdateSettingsRequest.
audit_transport_actionTransport action, for example, cluster:admin/settings/update.
audit_settings_changesArray of setting-change objects, each containing setting, old_value, new_value, operation, and scope. Sensitive settings are hidden automatically.

Each object in audit_settings_changes contains the following fields.

Field nameDescription
settingFull parameter name, for example, cluster.max_shards_per_node.
old_valuePrevious parameter value, or null if the parameter was not set previously.
new_valueNew parameter value, or null if the parameter was removed.
operationEither set (a value was assigned) or removed (the value was reset to its default).
scopeEither persistent (preserved after restart) or transient (lost after restart).

Transport INDEX_SETTINGS_CHANGED Fields​

The following attributes are recorded when index settings change.

Field nameDescription
audit_request_effective_userUser who changed the settings.
audit_transport_request_typeRequest type, for example, UpdateSettingsRequest.
audit_transport_actionTransport action, for example, indices:admin/settings/update.
audit_trace_indicesIndex names specified in the request. May contain wildcards and aliases.
audit_trace_resolved_indicesResolved index names affected by the request.
audit_settings_changesArray of setting-change objects, each containing setting, old_value, new_value, operation, and scope. Sensitive settings are hidden automatically.

Each object in audit_settings_changes contains the following fields.

Field nameDescription
settingFull parameter name, for example, index.number_of_replicas.
old_valuePrevious parameter value, or null if the parameter was not set previously.
new_valueNew parameter value, or null if the parameter was removed.
operationEither set (a value was assigned) or removed (the value was reset to its default).
scopeEither persistent (preserved after restart) or transient (lost after restart).