Please provide us a better solution.
Our setup is below and right now we need to monitor user activities in the linux server.

Filebeat -> logstash -> eS -> kibana

Please share whether we can use the same filebeat model to gather the logs or we can install & use the audit beat to gather the user log.


If you want low level info then use auditbeat, otherwise use filebeat to collect the system logs.

Thanks. I will use the filebeat modules and try to gather the logs.
But how to index the log values based on the input.
I need the same kind of output as in the auditbeat

Esp I need timestamp , process or command executed and user run the command


That will depend on what the logs contain.