How to get search queries executed by the users?

(Rohit Gupta) #1

I maintain multiple Graylog clusters and hundreds of users use it everyday. We need to know, what all search queries are being executed in different clusters. Is there any way to do it?

(Jochen) #2

You could use the access log for this:

(Rohit Gupta) #3

Thanks @jochen. This will help :slight_smile:

(John Buchanan) #4

I’ve configured my Elasticsearch hosts slowlog threshholds as well, and am pulling those in to Graylog to attempt to get even more info about what the users are executing.

(system) closed #5

