PluginBench
Skill
Fail
Audit score 45

kibana-audit

elastic/agent-skills

Enable and configure Kibana audit logging for saved object access, logins, and space operations.

What is kibana-audit?

Kibana audit logging tracks application-layer security events—saved object CRUD, login/logout, session activity, and space operations—via static configuration in kibana.yml. Use this skill to enable audit logging, filter noisy events, investigate access patterns, and correlate Kibana events with Elasticsearch audit logs using trace.id.

  • Enable or disable Kibana audit logging with rolling-file or console appenders
  • Configure audit log output, rotation policy, and file retention
  • Filter out noisy events (e.g. saved_object_find) using ignore_filters
  • Investigate saved object access, creation, update, and deletion events
  • Track user login/logout, session expiry, and access agreement acknowledgment
  • Monitor space creation, modification, and deletion operations

How to install kibana-audit

npx skills add https://github.com/elastic/agent-skills --skill kibana-audit
Prerequisites
  • Filesystem access to kibana.yml (self-managed) or Cloud console access (Elastic Cloud)
  • Gold, Platinum, Enterprise, or Trial license (audit logging requires paid tier)
  • Elasticsearch cluster endpoint for correlation queries against .security-audit-* index
Claude Code
Cursor
Windsurf
Cline

How to use kibana-audit

  1. 1.Edit kibana.yml and set xpack.security.audit.enabled: true
  2. 2.Configure the appender type (rolling-file or console) and output path
  3. 3.Optionally add ignore_filters to suppress noisy event actions or categories
  4. 4.Restart Kibana to apply changes
  5. 5.Verify audit events are being logged by checking the audit log file or console output
  6. 6.Extract trace.id from a Kibana audit event and query .security-audit-* to correlate with Elasticsearch events
  7. 7.(Optional) Configure Filebeat to ship Kibana audit logs to Elasticsearch for unified querying

Use cases

Good for
  • Enable audit logging for compliance and regulatory requirements (SOC 2, HIPAA, PCI-DSS)
  • Investigate who accessed or deleted a specific dashboard, visualization, or index pattern
  • Track unauthorized login attempts and session activity across Kibana spaces
  • Correlate a suspicious saved object deletion in Kibana with the underlying Elasticsearch operations using trace.id
  • Filter out high-volume saved_object_find events to reduce log noise and storage costs
Who it's for
  • Security and compliance engineers setting up audit trails
  • Kibana administrators investigating access or deletion incidents
  • DevOps teams shipping audit logs to centralized logging systems
  • Organizations requiring audit correlation across Kibana and Elasticsearch layers

kibana-audit FAQ

What is the difference between Kibana and Elasticsearch audit logging?

Kibana audit logs application-layer events (saved object CRUD, login/logout, space operations) that Elasticsearch does not see. Elasticsearch audit logs authentication failures, access grants/denials, and security config changes. Both use ECS format and share trace.id for correlation.

Do I need to restart Kibana after enabling audit logging?

Yes. Kibana audit is configured statically in kibana.yml, not via API. A restart is required for any changes to take effect.

How do I reduce audit log noise from high-volume events?

Use xpack.security.audit.ignore_filters in kibana.yml to suppress specific event actions (e.g. saved_object_find) or categories (e.g. database). An event is filtered if it matches all specified fields within a single filter entry.

How do I correlate a Kibana audit event with Elasticsearch operations?

Extract the trace.id from the Kibana audit event and search the .security-audit-* index for all events with the same trace.id. This shows all ES-level operations triggered by the Kibana action.

Can I query Kibana and Elasticsearch audit logs together?

Yes. Use Filebeat to ship the Kibana audit log file to an Elasticsearch index (e.g. kibana-audit-*), then query both .security-audit-* and kibana-audit-* together using a multi-index query filtered by trace.id.

Full instructions (SKILL.md)

Source of truth, from elastic/agent-skills.


name: kibana-audit description: > Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs. metadata: author: elastic version: 0.1.0

Kibana Audit Logging

Enable and configure audit logging for Kibana via kibana.yml. Kibana audit logs cover application-layer security events that Elasticsearch does not see: saved object CRUD (dashboards, visualizations, index patterns, rules, cases), login/logout, session expiry, space operations, and Kibana-level RBAC enforcement.

For Elasticsearch audit logging (authentication failures, access grants/denials, security config changes), see elasticsearch-audit. For authentication and API key management, see elasticsearch-authn. For roles and user management, see elasticsearch-authz.

For detailed event types, schema, and correlation queries, see references/api-reference.md.

Deployment note: Kibana audit configuration differs across deployment types. See Deployment Compatibility for details.

Jobs to Be Done

  • Enable or disable Kibana audit logging
  • Configure audit log output (rolling file, console)
  • Filter out noisy events (e.g. saved_object_find)
  • Investigate saved object access or deletion events
  • Track Kibana login/logout and session activity
  • Monitor space creation, modification, and deletion
  • Correlate Kibana audit events with Elasticsearch audit logs via trace.id
  • Ship Kibana audit logs to Elasticsearch for unified querying

Prerequisites

ItemDescription
Kibana accessFilesystem access to kibana.yml (self-managed) or Cloud console access (ECH)
LicenseAudit logging requires a gold, platinum, enterprise, or trial license
Elasticsearch URLCluster endpoint for correlation queries against .security-audit-*

Prompt the user for any missing values.

Enable Kibana Audit Logging

Kibana audit is configured statically in kibana.yml (not via API). A Kibana restart is required after changes.

xpack.security.audit.enabled: true
xpack.security.audit.appender:
  type: rolling-file
  fileName: /path/to/kibana/data/audit.log
  policy:
    type: time-interval
    interval: 24h
  strategy:
    type: numeric
    max: 10

To disable, set xpack.security.audit.enabled to false and restart Kibana.

Appender types

TypeDescription
rolling-fileWrites to a file with rotation policy. Recommended.
consoleWrites to stdout. Useful for containerized deployments.

Event Types

Kibana audit events use ECS format with the same core fields as ES audit (event.action, event.outcome, user.name, trace.id, @timestamp) plus Kibana-specific fields like kibana.saved_object.type, kibana.saved_object.id, and kibana.space_id.

Key event actions:

Event actionDescriptionCategory
saved_object_createA saved object was createddatabase
saved_object_getA saved object was readdatabase
saved_object_updateA saved object was updateddatabase
saved_object_deleteA saved object was deleteddatabase
saved_object_findA saved object search was performeddatabase
saved_object_open_point_in_timeA PIT was opened on saved objectsdatabase
saved_object_close_point_in_timeA PIT was closed on saved objectsdatabase
saved_object_resolveA saved object was resolved (alias redirect)database
loginA user logged in (success or failure)authentication
logoutA user logged outauthentication
session_cleanupAn expired session was cleaned upauthentication
access_agreement_acknowledgedA user accepted the access agreementauthentication
space_createA Kibana space was createdweb
space_updateA Kibana space was updatedweb
space_deleteA Kibana space was deletedweb
space_getA Kibana space was retrievedweb

See references/api-reference.md for the complete event schema.

Filter Policies

Suppress noisy events using ignore_filters in kibana.yml:

xpack.security.audit.ignore_filters:
  - actions: [saved_object_find]
    categories: [database]
Filter fieldTypeDescription
actionslistEvent actions to ignore
categorieslistEvent categories to ignore

An event is filtered out if it matches all specified fields within a single filter entry.

Correlate with Elasticsearch Audit Logs

When Kibana makes requests to Elasticsearch on behalf of a user, both systems record the same trace.id (passed via the X-Opaque-Id header). This is the primary key for correlating events across the two audit logs.

Prerequisite: Elasticsearch audit must be enabled via the cluster settings API. See the elasticsearch-audit skill for setup instructions, event types, and ES-specific filter policies.

Correlation workflow

  1. Find the suspicious event in the Kibana audit log.
  2. Extract its trace.id value.
  3. Search the ES audit index (.security-audit-*) for all events with the same trace.id.
  4. Review the combined timeline to understand what ES-level operations the Kibana action triggered.

The elasticsearch-audit skill also documents this workflow from the ES side — use it when starting from an ES audit event and looking for the originating Kibana action.

Search ES audit by trace ID

Given a suspicious Kibana event (e.g. a saved object deletion), extract its trace.id and search the ES audit index:

curl -X POST "${ELASTICSEARCH_URL}/.security-audit-*/_search" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "query": {
      "bool": {
        "filter": [
          { "term": { "trace.id": "'"${TRACE_ID}"'" } },
          { "range": { "@timestamp": { "gte": "now-24h" } } }
        ]
      }
    },
    "sort": [{ "@timestamp": { "order": "asc" } }]
  }'

Secondary correlation fields: user.name, source.ip, and @timestamp (time-window joins).

Ship Kibana audit logs to Elasticsearch

To query Kibana audit events alongside ES audit events, ship the Kibana audit log file to an Elasticsearch index using Filebeat:

filebeat.inputs:
  - type: log
    paths: ["/path/to/kibana/data/audit.log"]
    json.keys_under_root: true
    json.add_error_key: true

output.elasticsearch:
  hosts: ["https://localhost:9200"]
  index: "kibana-audit-%{+yyyy.MM.dd}"

Once indexed, both .security-audit-* (ES) and kibana-audit-* (Kibana) can be searched together using a multi-index query filtered by trace.id.

Examples

Enable Kibana audit for compliance

Request: "Enable Kibana audit logging and keep 10 rotated log files."

xpack.security.audit.enabled: true
xpack.security.audit.appender:
  type: rolling-file
  fileName: /var/log/kibana/audit.log
  policy:
    type: time-interval
    interval: 24h
  strategy:
    type: numeric
    max: 10

Restart Kibana after applying.

Investigate a deleted dashboard

Request: "Someone deleted a dashboard. Check the Kibana audit log."

Search the Kibana audit log (or the indexed kibana-audit-* data) for saved_object_delete events with kibana.saved_object.type: dashboard. Extract the trace.id and cross-reference with the ES audit index to see the underlying Elasticsearch operations.

Reduce audit noise from saved object searches

Request: "Kibana audit logs are too large because of constant saved_object_find events."

xpack.security.audit.ignore_filters:
  - actions: [saved_object_find]
    categories: [database]

This suppresses high-volume read operations while preserving create, update, and delete events.

Guidelines

Always enable alongside Elasticsearch audit

For full coverage, enable audit in both kibana.yml and Elasticsearch. Without Kibana audit, saved object access and Kibana login events are invisible. Without ES audit, cluster-level operations are invisible. See the elasticsearch-audit skill for ES-side setup.

Use trace.id for correlation

When investigating a Kibana event, always extract trace.id and search the ES audit index (.security-audit-*). This reveals the full chain of operations triggered by a single Kibana action. See Correlate with Elasticsearch Audit Logs above for queries.

Filter noisy read events

saved_object_find generates very high volume on busy Kibana instances. Suppress it unless you specifically need to audit read access.

Ship logs to Elasticsearch for unified querying

Kibana audit logs are written to files by default. Ship them to Elasticsearch via Filebeat for programmatic querying alongside ES audit events.

Rotate and retain appropriately

Configure rolling-file rotation to avoid filling the disk. A 30-90 day retention is typical for compliance.

Deployment Compatibility

CapabilitySelf-managedECHServerless
Kibana audit (kibana.yml)YesVia Cloud UINot available
Rolling-file appenderYesVia Cloud UINot available
Console appenderYesYesNot available
Ignore filtersYesVia Cloud UINot available
Correlate via trace.idYesYesNot available
Ship to ES via FilebeatYesYesNot available

ECH notes: Kibana audit is enabled via the deployment edit page in the Cloud console. Log files are accessible through the Cloud console deployment logs.

Serverless notes:

  • Kibana audit logging is not user-configurable on Serverless. Security events are managed by Elastic as part of the platform.
  • If a user asks about Kibana auditing on Serverless, direct them to the Elastic Cloud console or their account team.