# How to log user query?

**URL:** <https://community.graylog.org/t/how-to-log-user-query/19662>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, debuggingpl\
**Created:** [April 29, 2021, 6:36am UTC](https://community.graylog.org/t/how-to-log-user-query/19662 "2021-04-29T06:36:44Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [April 29, 2021, 9:56pm UTC](https://community.graylog.org/t/how-to-log-user-query/19662/2 "2021-04-29T21:56:03Z")

</div>

Hello,

Maybe I can help answer your question.

> [@Jin](#):
>
> To figure out, I want to log `who` executed a `query` in every search.  
> I found “user activity log” but it doesn’t write which query user send.

For tracking users activities, The Enterprise version might be able to handle this.Unfortunately, I do not use Enterprise version so I’m not completely sure.

[https://docs.graylog.org/en/4.0/pages/auditlog/usage.html](https://docs.graylog.org/en/4.0/pages/auditlog/usage.html)

In my environment I had to do a work around for user activities as follow.  
I’m using Graylog 4.0.6 with NXlog shipper.

[https://docs.graylog.org/en/4.0/pages/secure/sec\_log\_user\_activity.html#logging-user-activity](https://docs.graylog.org/en/4.0/pages/secure/sec_log_user_activity.html#logging-user-activity)

I had to configure NXLog to read restaccess.log file.

Once that was done, I create an extractor Graylog Input called “graylog\_gui” and then created a widget from that field.

Graylog Version 3.3.x displays the full name of the users, Example I’ll use my name as shown in bold print.

> 2021-04-09 22:23:44,520 DEBUG: org.graylog2.rest.accesslog – 10.10.10.10 **greg.smith** [-] “GET api/system/cluster/nodes” Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 200 -1

As of Graylog version 4.0.6 users are displayed as a GUID as shown in bold print.

> 2021-04-09 22:23:44,520 DEBUG: org.graylog2.rest.accesslog – 10.10.10.10 **5e224e7683d72eff75055199** [-] “GET api/system/cluster/nodes” Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 200 -1

I had to create a pipeline to turn the sting 5e224e7683d72eff75055199 → greg.smith as shown below.

```
rule "Graylog Web Access Greg"
when
    has_field("graylog_gui") AND contains(to_string($message.graylog_gui), "5e224e7683d72eff75055199")
then
    set_field("graylog_gui","greg.smith");
end

```

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/c0bfb82fc0fb8eb4b15f699e6a4d9835f8183302.png)

> [@Jin](#):
>
> To figure out, I want to log `who` executed a `query` in every search

I havent doent that before, maybe someone else has.  
Hope this helps

---

_[View the full topic](https://community.graylog.org/t/how-to-log-user-query/19662)._
