# Audit log

**URL:** <https://discuss.elastic.co/t/audit-log/167976>\
**Category:** Logstash\
**Created:** [February 12, 2019, 7:54am UTC](https://discuss.elastic.co/t/audit-log/167976 "2019-02-12T07:54:01Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![nandha\_88](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Post date:** [February 12, 2019, 7:54am UTC](https://discuss.elastic.co/t/audit-log/167976/1 "2019-02-12T07:54:02Z")

</div>

Hi All,

Please provide us a better solution.  
Our setup is below and right now we need to monitor user activities in the linux server.

Filebeat -\> logstash -\> eS -\> kibana

Please share whether we can use the same filebeat model to gather the logs or we can install & use the audit beat to gather the user log.

Regards  
Nandha

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 12, 2019, 7:56am UTC](https://discuss.elastic.co/t/audit-log/167976/2 "2019-02-12T07:56:23Z")

</div>

If you want low level info then use auditbeat, otherwise use filebeat to collect the system logs.

---

<div class="post-metadata">

**Author:** ![nandha\_88](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Post date:** [February 12, 2019, 8:08am UTC](https://discuss.elastic.co/t/audit-log/167976/3 "2019-02-12T08:08:29Z")

</div>

Hi Warkolm,

Thanks. I will use the filebeat modules and try to gather the logs.  
But how to index the log values based on the input.  
I need the same kind of output as in the auditbeat

Esp I need timestamp , process or command executed and user run the command

Regards  
Nandha

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 12, 2019, 8:19am UTC](https://discuss.elastic.co/t/audit-log/167976/4 "2019-02-12T08:19:43Z")

</div>

That will depend on what the logs contain.

---

<div class="post-metadata">

**Author:** ![nandha\_88](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Post date:** [February 18, 2019, 5:17pm UTC](https://discuss.elastic.co/t/audit-log/167976/5 "2019-02-18T17:17:56Z")

</div>

Hi Warolm,

I have installed ELK in the fresh server as the below setup

ELK installed in one server  
filebeat installed in the client machine with systemd and auditd module enabled

I have give the logstash IP in the filebeabt.yml to forward the log.

Please share the step to load the index which will give the system and auditd columns

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 18, 2019, 6:20pm UTC](https://discuss.elastic.co/t/audit-log/167976/6 "2019-02-18T18:20:43Z")

</div>

What do the logfile entries look like?

---

<div class="post-metadata">

**Author:** ![nandha\_88](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Post date:** [February 20, 2019, 7:38pm UTC](https://discuss.elastic.co/t/audit-log/167976/7 "2019-02-20T19:38:20Z")

</div>

Hi Badger,

BAsed on my search , what I see the below command should be run to enable the auditd index when logstash is used to collect the logs.

filebeat setup --pipelines --modules auditd

[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-quickstart.html#load-ingest-pipelines](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-quickstart.html#load-ingest-pipelines)

Should I need to run this on all hosts which have filebeat installed or just only in the eLK server ?

Regards  
Nandha

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2019, 10:57pm UTC](https://discuss.elastic.co/t/audit-log/167976/8 "2019-02-20T22:57:42Z")

</div>

> **Nope**
>
> It needs to be on all hosts you want to collect that info from.

Sorry I misread that one. You don't need to run the setup on every host. You do need to enable the module on every host.

---

<div class="post-metadata">

**Author:** ![nandha\_88](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Post date:** [February 21, 2019, 4:53pm UTC](https://discuss.elastic.co/t/audit-log/167976/9 "2019-02-21T16:53:35Z")

</div>

Hi Warkolm,

I have enabled the audit module in the filebeat and able to see the harvester for the audit.log when I restart the filebeat.

Now the logs are not shipped into logstash and end with the below error. Please help.

{"source":"/var/log/audit/audit.log","prospector":{"type":"log"},"beat":{"version":"6.2.2","name":"[test.example.com](http://test.example.com)","hostname":"[test.example.com](http://test.example.com)"},"message":"type=EXECVE msg=audit(1550767742.671:15104841): argc=3 a0="sed" a1="-e" a2="s|:|\\:|"","offset":7677297,"host":"[test.example.com](http://test.example.com)","@timestamp":"2019-02-21T16:49:09.398Z","@version":"1","fileset":{"module":"auditd","name":"log"},"tags":["beats\_input\_codec\_plain\_applied","\_grokparsefailure"]

Once this issue completed , I will check with index fields.

Regards  
Nandha

---

<div class="post-metadata">

**Author:** ![nandha\_88](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Post date:** [February 26, 2019, 6:10am UTC](https://discuss.elastic.co/t/audit-log/167976/10 "2019-02-26T06:10:22Z")

</div>

Hi All,

I started using the auditbeat module.  
Please share the rule to add to auditbeat.yml to record all the commands running in the system and forward to elasticsearch

Regards  
Nandha

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2019, 6:18am UTC](https://discuss.elastic.co/t/audit-log/167976/11 "2019-03-26T06:18:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
