elasticsearch-audit

Official

Secure your cluster with audit logs.

Authorelastic
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps you enable, configure, and query Elasticsearch security audit logs to monitor and investigate security-related events within your cluster.

Core Features & Use Cases

  • Enable/Disable Audit Logging: Turn audit logging on or off via cluster settings.
  • Configure Event Types: Select specific events to record (e.g., authentication failures, access denials) or exclude noisy ones.
  • Filter Policies: Create rules to ignore specific events from certain users, realms, or indices.
  • Query Audit Events: Search for specific security events like failed logins or unauthorized access attempts.
  • Correlate with Kibana: Link Elasticsearch audit events with Kibana audit events using trace.id.
  • Use Case: Investigate a series of failed login attempts by searching audit logs for authentication_failed events within a specific time frame and from a particular IP address.

Quick Start

Enable audit logging and record all failed access and authentication events.

Dependency Matrix

Required Modules

None required

Components

references

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: elasticsearch-audit
Download link: https://github.com/elastic/agent-skills/archive/main.zip#elasticsearch-audit

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.