Audit log


(nandha) #1

Hi All,

Please provide us a better solution.
Our setup is below and right now we need to monitor user activities in the linux server.

Filebeat -> logstash -> eS -> kibana

Please share whether we can use the same filebeat model to gather the logs or we can install & use the audit beat to gather the user log.

Regards
Nandha


(Mark Walkom) #2

If you want low level info then use auditbeat, otherwise use filebeat to collect the system logs.


(nandha) #3

Hi Warkolm,

Thanks. I will use the filebeat modules and try to gather the logs.
But how to index the log values based on the input.
I need the same kind of output as in the auditbeat

Esp I need timestamp , process or command executed and user run the command

Regards
Nandha


(Mark Walkom) #4

That will depend on what the logs contain.