Skip to content

Shield Audit Log to optionally include Roles of a user #30032

@elasticmachine

Description

@elasticmachine

Original comment by @skearns64:

The Shield Audit Log should optionally include the roles of the user. For auditing purposes, some users want to know what role(s) a user had at the time they were making a given request.

In some cases, it may be desirable to show only the roles that contain privileges that grant access to the resources used in the request, though this seems like a nice-to-have - there is significant value to recording roles even without this features.

Another use-case for this feature is tracking how groups (identified by their roles) are using the application/cluster

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions