Skip to content

Support audit ignore policy by request.name #123998

Open
@jguay

Description

@jguay

Description

auditing filtering does not currently allow to filter by request.name, example here user wants to filter out request BulkItemRequest to reduce size of audit logs

{
  "type": "audit",
  "timestamp": "2025-01-01T01:23:45,678+0000",
  "node.id": "G7bXq2vL9pZmT4KdYwNr5C",
  "event.type": "transport",
  "event.action": "access_granted",
  "authentication.type": "REALM",
  "user.name": "user_name",
  "user.run_by.name": "user_name",
  "user.realm": "realm_name",
  "user.run_by.realm": "reserved",
  "user.roles": [
    "superuser"
  ],
  "origin.type": "rest",
  "origin.address": "1.2.3.4:12345",
  "request.id": "aP8XzY3kWmVqL7J9oT5Rb",
  "action": "indices:data/write/delete",
  "request.name": "BulkItemRequest",
  "indices": [
    "my-index"
  ],
  "x_forwarded_for": "127.0.0.1"
}

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions