Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Auditing dashboard #17873

Closed
elasticmachine opened this issue Feb 10, 2017 · 10 comments
Closed

Auditing dashboard #17873

elasticmachine opened this issue Feb 10, 2017 · 10 comments
Labels
blocked Feature:New Feature New feature not correlating to an existing feature label impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. loe:small Small Level of Effort release_note:enhancement Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!

Comments

@elasticmachine
Copy link
Contributor

elasticmachine commented Feb 10, 2017

Original comment by @markwalkom:

This was asked on the forums, here and Uri mentioned there is nothing official.

So can we make something official, like we have for the Watcher history?

Blocked on elastic/integrations#368

@elasticmachine
Copy link
Contributor Author

Original comment by @skearns64:

I made a prototype of this a rather long time ago here: LINK REDACTED

I expect it will need updating, but it's at least a reference point

@elasticmachine
Copy link
Contributor Author

Original comment by @clintongormley:

Now that Shield can directly index the Shield audit logs, we can provide an example dashboard in our docs based on this data.

Now we can ship this directly in X-Pack UI, no?

@elasticmachine
Copy link
Contributor Author

Original comment by @uboness:

Yes and no... Having a dashboard is great, but more importantly we need a proper (simple) UI that simply enables one to search the audit logs... That's something we should tackle for 5.x... I believe it's relatively a low hanging fruit, so rather early 5.x than late.

"the "problem" with putting the dashboard in today is that it won't fit the UX we want to promote (audit logs UI should either be part of monitoring or security management)

@elasticmachine
Copy link
Contributor Author

Original comment by @tbragin:

This seems closely related to an issue I filed earlier: LINK REDACTED If the ask is to audit Kibana dashboard usage, one of the issues is that we are currently not logging this at all, as all the activity happens on the client.

@elasticmachine
Copy link
Contributor Author

Original comment by @jaymode:

If the ask is to audit Kibana dashboard usage, one of the issues is that we are currently not logging this at all, as all the activity happens on the client.

I think the ask is different; this is about a out of the box dashboard to visualize the indexed audit events from elasticsearch with shield

@elasticmachine
Copy link
Contributor Author

Original comment by @markwalkom:

@jaymode is correct.

@timroes timroes added Feature:New Feature New feature not correlating to an existing feature label and removed :Management DO NOT USE labels Nov 27, 2018
@timroes timroes added the Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! label Mar 11, 2021
@elasticmachine
Copy link
Contributor Author

Pinging @elastic/kibana-security (Team:Security)

@legrego
Copy link
Member

legrego commented Mar 11, 2021

We will be in a better position to support something like this once we have migrated the Kibana module to to an Elastic integration (elastic/integrations#368). I'm going to mark this as blocked in the meantime.

This will also give us more time to expand our recently updated audit logging capabilities

@exalate-issue-sync exalate-issue-sync bot added impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. loe:small Small Level of Effort labels Aug 5, 2021
@legrego
Copy link
Member

legrego commented Nov 8, 2021

Our Observability and Security solutions are tailored for monitoring the types of events that we generate in Kibana's audit logs. This largely works out-of-the-box now that Kibana's audit logger is ECS-compliant.

@elastic/kibana-security any objections to closing this in favor of using & improving the built-in solutions for this type of analysis?

@jportner
Copy link
Contributor

jportner commented Nov 8, 2021

any objections to closing this in favor of using & improving the built-in solutions for this type of analysis?

Agree, I think we can close this

@legrego legrego closed this as completed Nov 9, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
blocked Feature:New Feature New feature not correlating to an existing feature label impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. loe:small Small Level of Effort release_note:enhancement Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!
Projects
None yet
Development

No branches or pull requests

4 participants