Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.
---
name: elasticsearch-audit
description: >
Enable, configure, and query Elasticsearch security audit logs. Use when the task
involves audit logging setup, event filtering, or investigating security incidents
like failed logins.
metadata:
author: elastic
version: 0.1.0
---
# Elasticsearch Audit Logging
Enable and configure security audit logging for Elasticsearch via the cluster settings API. Audit logs record security
events such as authentication attempts, access grants and denials, role changes, and API key operations — essential for
compliance and incident investigation.
For Kibana audit logging (saved object access, login/logout, space operations), see **kibana-audit**. For authentication
and API key management, see **elasticsearch-authn**. For roles and user management, see **elasticsearch-authz**. For
diagnosing security errors, see **elasticsearch-security-troubleshooting**.
For detailed API endpoints and event types, see [references/api-reference.md](references/api-reference.md).
> **Deployment note:** Audit logging configuration differs across deployment types. See
> [Deployment Compatibility](#deployment-compatibility) for details.… install to load the full skillIn any Claude conversation, say:
Install the Elasticsearch Audit skill
It activates automatically in your next session.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp