Audit trail log delivery
Audit trail is the first log type available for log delivery in Elastic Cloud Serverless. Enabling it delivers audit logs to your selected destination project so you can track and investigate organization actions in the source project.
An audit trail includes the following events:
- Elastic Cloud and organization administration: Sign-in, membership, IAM, and project settings where applicable
- Project activity: Elasticsearch and Kibana on the project — index, template, and pipeline lifecycle; data searches, reads, and writes; Kibana saved-object and UI access.
Delivering an audit trail into a project lets you investigate end-to-end activity in one place. For example, you can:
- Trace failed or successful sign-ins for a user
- Review membership, IAM, or project-admin changes
- Investigate access denied on an index pattern
- Track create, update, or delete actions on indices, templates, or pipelines
- Detect changes or deletions of Kibana saved objects such as detection rules
- Determine who searched a sensitive index
- Follow one user journey across
service.namevalues for the sameuser.nameand time window
Complete the following steps to configure log delivery in your project.
You must have the Admin or Editor role on the source project.
- On your Elastic Cloud homepage, find the project that should be the source of your log deliveries and select Manage.
- From the navigation menu, select Log delivery.
- For Audit trail, complete the following fields.
- In the Destination column, select one or more Elastic Security Serverless or Elastic Observability Serverless projects to receive the logs.
Tip
We recommend selecting an Elastic Security Serverless project as the destination for your audit trail.
- Choose ignore filters to exclude certain events before delivery. Leave the list empty only if you want to deliver all events for that log type.
- Switch the toggle to Enabled.
- In the Destination column, select one or more Elastic Security Serverless or Elastic Observability Serverless projects to receive the logs.
- Select Save.
Apply ignore filters to exclude certain events from being delivered. Refer to Log delivery in Elastic Cloud Serverless > Ignore filters to learn more about their impact on your delivery volume and bill.
The following table describes which ignore filters are available for the audit trail log type, when to select them, and how much they reduce your delivery volume.
| Name | When to select | Approx. volume cut |
|---|---|---|
| Ignore data searches and reads | Select to exclude the highest-volume events on search-heavy projects. Do not select if you need evidence of who searched or read data (for example, HIPAA or PCI). On by default. |
~50–70% |
| Ignore data writes | Select when you want configuration and object-change evidence without ingest and bulk write volume. | ~5–15% |
| Ignore successful sign-ins | Select for SOC or minimal profiles that focus on failures. Do not select if you need successful sign-in accountability. Applies to authentication events in the unified audit trail, including Elastic Cloud and organization signals when present. | ~5–15% |
| Ignore routine user and role checks | Select for SOC or minimal profiles that focus on failures. Do not select if you need IAM accountability. Applies to IAM-related events in the unified audit trail, including Elastic Cloud and organization signals when present. | ~2–5% |
| Ignore UI requests | Select to exclude read-only UI navigation noise. Saved-object mutations are still delivered. On by default. |
~10–20% |
| Combination | Ignore filters to select | Est. volume | Typical use |
|---|---|---|---|
| Balanced (UI default) | Data reads, UI views | Moderate | General production |
| Full audit trail | (none) | Full | Forensics / maximum end-to-end evidence |
| Compliance (changes and sign-ins) | Data reads | Elevated | Change accountability without search noise |
| Security events only | Data reads, UI views, successful authentications | Low | Failure-oriented monitoring |
| Admin and configuration | Data reads, UI views, data writes | Low | ITGC / change management |
| Minimal | All five | Minimal | Dev / sandbox |
For Security events only, successful sign-ins are ignored when that filter is on, so the Security column is failure-oriented. Security and Admin columns include Elastic Cloud and organization signals when those events are present in the delivered trail.
These starting points are not legal advice. Validate retention, scope, and evidence requirements with your compliance team.
| Need | Start from | Important |
|---|---|---|
| HIPAA / PCI (data access evidence) | Full audit trail | Do not enable Ignore data searches and reads |
| GDPR (accountability) | Balanced or Compliance | Enable the data-reads ignore unless access proof is required |
| SOX (ITGC) | Compliance or Admin and configuration | — |
| Dev / test | Minimal | Enable all ignore filters |
Explore delivered audit trail logs in the following locations on your destination project:
| Data stream or index pattern | Contents |
|---|---|
logs-serverless.audit.otel-elastic_cloud |
Project-level audit logs (Elasticsearch, Kibana, and Elastic Cloud project signals) |
logs-org.audit.otel-elastic_cloud |
Organization-level audit logs (administration, configuration, billing, and similar) |
logs-*.audit.otel-* |
All audit logs |
Use Discover or ES|QL to investigate these logs. Useful fields to query on include:
@timestampuser.*event.action/event.category/event.type/event.outcomesource.ipproject.idorganization.idservice.name- Producer-specific fields
Additionally, use AutoOps on the destination project to monitor your ingest rate and storage retained.