---
title: Elasticsearch domains should have audit logs enabled
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Elasticsearch domains should have audit
  logs enabled
---

# Elasticsearch domains should have audit logs enabled
 
## Description{% #description %}

This control confirms that audit logging is enabled for Elasticsearch domains. Audit logs allow extensive customization, enabling the monitoring of user activities in Elasticsearch clusters. This includes tracking both successful and failed authentication attempts, OpenSearch requests, index modifications, and incoming search queries. This check only verifies that audit logging is enabled, and does not require specific parameters.

## Remediation{% #remediation %}

For detailed instructions on enabling audit logging, see [Enabling audit logs in the Amazon OpenSearch Service Developer Guide](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/audit-logs.html#audit-log-enabling).
