Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Additional audit logging events #32444

Open
seang-es opened this issue Jul 27, 2018 · 4 comments
Open

Additional audit logging events #32444

seang-es opened this issue Jul 27, 2018 · 4 comments
Labels
>enhancement :Security/Audit X-Pack Audit logging Team:Security Meta label for security team

Comments

@seang-es
Copy link

We've seen requests for additional audit logging events:

. Creation of application roles/profiles
. Modification of roles/profiles
. Changes to system security configuration
. Manual change to the non security related configuration which effects service function
. Log integrity events
. Manual log deletion or stoppage

Log integrity and log deletion events may be something we cannot catch, but we'd like to investigate this. Changes to files that are reloaded by the node seem to be something we could log on, as well as API-based changes to security settings.

Thanks!

@seang-es seang-es added >enhancement :Security/Audit X-Pack Audit logging labels Jul 27, 2018
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security

@elastic elastic deleted a comment from cbryanvest Aug 21, 2018
@AlexGorshunov
Copy link

UP
Thats really important for us.

As System Administrator and Security auditor, I would like to have information about all changes in the role (create/update/delete) in audit log. I would like to see who? and how? changed the role, which permission was (add/changed/deleted)

@AlexGorshunov

This comment has been minimized.

@AlexGorshunov
Copy link

Up, we still waiting for this feature

@rjernst rjernst added the Team:Security Meta label for security team label May 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
>enhancement :Security/Audit X-Pack Audit logging Team:Security Meta label for security team
Projects
None yet
Development

No branches or pull requests

4 participants