Skip to content

Allow audit logging to be turned on/off without server restart - #147333

Merged
ankit--sethi merged 27 commits into
elastic:mainfrom
ankit--sethi:feature/change-audit-settings-without-restart
May 11, 2026
Merged

ankit--sethi merged 27 commits into
elastic:mainfrom
ankit--sethi:feature/change-audit-settings-without-restart

Conversation

@ankit--sethi

@ankit--sethi ankit--sethi commented Apr 23, 2026 •

Copy link
Copy Markdown

Currently the setting xpack.security.audit.enabled requires a server restart to flip on/off since AuditTrailService is initialized in Security.java with a null/non-null LoggingAuditTrail instance based on the setting value.

This change updates AuditTrailService to always hold a reference to a working LoggingAuditTrail instance; whether it gets used or not is gated by the current value of the setting.

The setting itself is updated to be Setting.Property.Dynamic and AuditTrailService will now check its current value to switch between regular audit logging or a no-op.

Various tests are adjusted to work with this change, plus three new integration tests that cover an ES server turning on with the setting on/off/unset respectively, and then flipping its value back and forth. Each integration tests uses the PUT /_cluster/settings API to update xpack.security.audit.enabled, and uses the GET /_security/_authenticate API to trigger an access_granted audit event (or lack thereof).

…rt since AuditTrailService is initialized or not based on its value during server start. This change updates the code to always have AuditTrailService/LoggingAuditTrail ready to go, gated by current value of the setting.

The setting is updated to be dynamic and AuditTrailService is updated to check its current value to switch between regular audit operations or a no-op.

Various tests are adjusted to work with this change, plus three new integration tests that cover an ES server turning on with the setting on/off/unset respectively, and then flipping its value back and forth.
@ankit--sethi
ankit--sethi requested a review from a team April 23, 2026 18:00
@ankit--sethi ankit--sethi self-assigned this Apr 23, 2026
@elasticsearchmachine elasticsearchmachine added the Team:Security Meta label for security team label Apr 23, 2026
@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

Pinging @elastic/es-security (Team:Security)

@ankit--sethi ankit--sethi added v9.5.0 auto-backport Automatically create backport pull requests when merged v8.19.16 v9.3.5 v9.4.1 labels Apr 23, 2026
elasticsearchmachine and others added 3 commits April 23, 2026 18:07
@ankit--sethi ankit--sethi changed the title Allow audit logging to turned on/off without server restart Allow audit logging to be turned on/off without server restart Apr 23, 2026
elasticsearchmachine and others added 3 commits April 23, 2026 21:23

@ebarlas ebarlas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work overall. Gating at AuditTrailService.get() is a tidy solution. End-to-end coverage of the three startup states and the runtime toggle is good.

I offered a handful of suggestions, ranging from docs to code clean-up and organization.

if (isAuditEnabled == false) {
return NOOP_AUDIT_TRAIL;
}
if (auditTrail != null) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since auditTrail is no longer nullable, this branching logic can be removed.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

removed

/**
* Manages the lifecycle, mapping and data upgrades/migrations of the {@code RestrictedIndicesNames#SECURITY_MAIN_ALIAS}
* and {@code RestrictedIndicesNames#SECURITY_MAIN_ALIAS} alias-index pair.
* Manages the lifecycle, mapping and data upgrades/migrations of the {@link SecuritySystemIndices#SECURITY_MAIN_ALIAS}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems unrelated. Was it intended?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

removed

public class AuditLoggingDefaultAtStartupDynamicSwitchingTests extends AuditLoggingOffAtStartupDynamicSwitchingTests {

@Override
protected boolean addMockHttpTransport() {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This override isn't needed. It's a duplicate of AuditLoggingOffAtStartupDynamicSwitchingTests.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the abstract base class change covers these and the rest of the issues

return Settings.builder().put(super.nodeSettings(nodeOrdinal, otherSettings)).remove(XPackSettings.AUDIT_ENABLED.getKey()).build();
}

public void testFlippingAuditLogFalseToTrueToFalse() throws IOException {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing @Override.

public class AuditLoggingOnAtStartupDynamicSwitchingTests extends AuditLoggingOffAtStartupDynamicSwitchingTests {

@Override
protected boolean addMockHttpTransport() {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This override isn't needed. It's a duplicate of AuditLoggingOffAtStartupDynamicSwitchingTests.

.build();
}

public void testFlippingAuditLogFalseToTrueToFalse() throws IOException {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing @Override.

import java.io.IOException;

@ESIntegTestCase.ClusterScope(scope = ESIntegTestCase.Scope.TEST, numDataNodes = 1)
public class AuditLoggingOffAtStartupDynamicSwitchingTests extends SecurityIntegTestCase {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For clarity, you might consider a slightly different arrangement with an abstract base class and three concrete subclasses. The off-at-start concrete base class with test method overrides is somewhat surprising.

For example:

public abstract class AbstractAuditLoggingDynamicSwitchingTestCase extends SecurityIntegTestCase {
    ...
    @Override
    protected final Settings nodeSettings(int nodeOrdinal, Settings otherSettings) {
        ...
        startupAuditEnabled().ifPresent(value -> builder.put(XPackSettings.AUDIT_ENABLED.getKey(), value));
        ...
    }
    ...
    protected abstract Optional<Boolean> startupAuditEnabled();
    ...
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

agreed, I was getting lazy here, thanks!

false,
Setting.Property.NodeScope
Setting.Property.NodeScope,
Setting.Property.Dynamic

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider including corresponding edits in docs/reference/elasticsearch/configuration-reference/auding-settings.md

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ooh yeah that was a miss. There might also be some other doc updates downstream of merging this. I'll check.

public AuditTrailService(AuditTrail auditTrail, XPackLicenseState licenseState, ClusterService clusterService) {
this.auditTrail = auditTrail;
this.licenseState = licenseState;
clusterService.getClusterSettings().initializeAndWatch(XPackSettings.AUDIT_ENABLED, newValue -> isAuditEnabled = newValue);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider adding a log statement in the settings callback to highlight the audit change.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice idea!

@ankit--sethi
ankit--sethi requested a review from a team as a code owner May 5, 2026 16:27
@github-actions

github-actions Bot commented May 5, 2026 •

Copy link
Copy Markdown
Contributor

🔍 Preview links for changed docs

@github-actions

github-actions Bot commented May 5, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Important: Docs version tagging

👋 Thanks for updating the docs! Just a friendly reminder that our docs are now cumulative. This means all 9.x versions are documented on the same page and published off of the main branch, instead of creating separate pages for each minor version.

We use applies_to tags to mark version-specific features and changes.

Expand for a quick overview

When to use applies_to tags:

✅ At the page level to indicate which products/deployments the content applies to (mandatory)
✅ When features change state (e.g. preview, ga) in a specific version
✅ When availability differs across deployments and environments

What NOT to do:

❌ Don't remove or replace information that applies to an older version
❌ Don't add new information that applies to a specific version without an applies_to tag
❌ Don't forget that applies_to tags can be used at the page, section, and inline level

🤔 Need help?

ankit--sethi and others added 4 commits May 5, 2026 13:27
docs update

Co-authored-by: shainaraskas <58563081+shainaraskas@users.noreply.github.com>
…thout-restart' into feature/change-audit-settings-without-restart
@ankit--sethi
ankit--sethi requested a review from ebarlas May 6, 2026 21:03

@ebarlas ebarlas left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! I added a few additional comments about docs and PR labels.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The section needs to be updated as well to reflect the dynamic setting change.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.


This setting can be changed at runtime using the [cluster update settings API](https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-cluster-put-settings) without requiring a node restart.

:::{note}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe this PR is an "enhancement", which means it will only be available in the next release, 9.5.0.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done here

@ankit--sethi ankit--sethi added >enhancement and removed >non-issue auto-backport Automatically create backport pull requests when merged v9.4.1 v9.3.5 v8.19.16 labels May 8, 2026
@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

Hi @ankit--sethi, I've created a changelog YAML for you.

@ankit--sethi
ankit--sethi merged commit 6a6d6ab into elastic:main May 11, 2026
43 checks passed
@ankit--sethi
ankit--sethi deleted the feature/change-audit-settings-without-restart branch May 11, 2026 16:51
drempapis pushed a commit to drempapis/elasticsearch that referenced this pull request May 13, 2026
…ic#147333)

* Currently the setting `xpack.security.audit.enabled` requires a restart since AuditTrailService is initialized or not based on its value during server start. This change updates the code to always have AuditTrailService/LoggingAuditTrail ready to go, gated by current value of the setting.

The setting is updated to be dynamic and AuditTrailService is updated to check its current value to switch between regular audit operations or a no-op.

Various tests are adjusted to work with this change, plus three new integration tests that cover an ES server turning on with the setting on/off/unset respectively, and then flipping its value back and forth.

* [CI] Auto commit changes from spotless

* fix tests

* [CI] Auto commit changes from spotless

* fix without breaking other things

* code review feedback

* fix tests

* Apply suggestions from code review

docs update

Co-authored-by: shainaraskas <58563081+shainaraskas@users.noreply.github.com>

* fix tests

* Update docs/changelog/147333.yaml

* tweak language and update versions to reflect this is an enhancement

* fix error

* fix - doc changes are cumulative so not deleting the sentence.

* fix - doc changes are cumulative so not deleting the sentence.

---------

Co-authored-by: elasticsearchmachine <infra-root+elasticsearchmachine@elastic.co>
Co-authored-by: shainaraskas <58563081+shainaraskas@users.noreply.github.com>
ankit--sethi pushed a commit to elastic/docs-content that referenced this pull request May 15, 2026
## Summary
Companion Docs PR to the update
[here](elastic/elasticsearch#147333). The audit
logging enabled/disabled setting has changed from static to dynamic for
version 9.5+.

## Generative AI disclosure
<!--
To help us ensure compliance with the Elastic open source and
documentation guidelines, please answer the following:
-->
1. Did you use a generative AI (GenAI) tool to assist in creating this
contribution?
- [x] Yes  
- [ ] No  

Claude Opus

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Vlada Chirmicci <vlada.chirmicci@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

>enhancement :Security/Audit X-Pack Audit logging Team:Security Meta label for security team v9.5.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants