# Argument \`path\` of the module file\_integrity enhancement?

**URL:** https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668
**Category:** Beats
**Tags:** auditbeat
**Created:** [January 6, 2022, 3:35pm UTC](https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668 "2022-01-06T15:35:35Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![krakz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krakz/32/99924_2.png) [@krakz](https://discuss.elastic.co/u/krakz)
#### Post date: [January 6, 2022, 3:35pm UTC](https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668/1 "2022-01-06T15:35:35Z")

</div>

Hi,

The module `file_integrity` takes a list of file path, which is useful for binary and configuration file monitoring, but generic users file cannot be monitored otherwise than with the option `recursive` enable.

Is there, any chance that argument `path` can be interpreted as a regular expression to ease file under `/home/<username>` to be monitored or is there another way to monitor these file (without the full file path)?

For example, monitoring file such as: `~/.ssh/authorized_keys` for all users would take the following configuration:

```auto
- module: file_integrity
  paths:
  - /bin
  - /etc
  - \/home\/.*\/\.ssh\/authorized_keys

```

_PCRE2 regexp format used above..._

Thank in advance for your support.

---

<div class="post-metadata">

### Author: ![samuel.john](https://avatars.discourse-cdn.com/v4/letter/s/82dd89/32.png) [@samuel.john](https://discuss.elastic.co/u/samuel.john)
#### Post date: [January 19, 2022, 9:05am UTC](https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668/2 "2022-01-19T09:05:33Z")

</div>

> **[File Integrity Module | Auditbeat Reference \[7.16\] | Elastic](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html)**

**`paths`** Globs are not supported. The specified paths should exist when the metricset is started. Paths should be absolute, although the file integrity module will attempt to resolve relative path events to their absolute file path.

```auto
- module: file_integrity
  paths:
  - /bin
  - /etc
  - /home/user1/.ssh/authorized_keys
  - /home/user2/.ssh/authorized_keys

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 16, 2022, 11:05am UTC](https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668/3 "2022-02-16T11:05:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
