# Auditbeat 7.13.0 vs 8.15.0 logs format

**URL:** <https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [September 10, 2024, 3:17am UTC](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279 "2024-09-10T03:17:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Pinch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_pinch/32/137448_2.png) [@Matt\_Pinch](https://discuss.elastic.co/u/Matt_Pinch)\
**Post date:** [September 10, 2024, 3:17am UTC](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279/1 "2024-09-10T03:17:25Z")

</div>

Upgrading from auditbeat 7.13.0 -\> 8.15.0.  
What differences are expected to be seen in the logs? Does 8.15.0 provide the same information as 7.13.0? Does the format change? Is it backward compatible?  
Thanks.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 10, 2024, 3:59am UTC](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279/2 "2024-09-10T03:59:48Z")

</div>

Hello and welcome,

Between 7.13.0 and 8.15.0 there are more than 3 years of changes, you will need to check the release notes from each version between them to really know what has changed.

You can start [here](https://www.elastic.co/guide/en/beats/libbeat/current/release-notes-7.13.0.html).

But to resume, the output from 8.15 should be basically the same from 7.13 with some improvements regarding parsing and things like that.

Also, it is not clear what you mean with backward compatible. What is compatible with what?

Auditbeat and Elasticsearch? Or Auditbeat and audit logs?

---

<div class="post-metadata">

**Author:** ![Matt\_Pinch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_pinch/32/137448_2.png) [@Matt\_Pinch](https://discuss.elastic.co/u/Matt_Pinch)\
**Post date:** [September 10, 2024, 4:54am UTC](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279/3 "2024-09-10T04:54:19Z")

</div>

Thank you for responding.  
By backwards compatible, I meant that we are relying on the structured data the logs from 7.13.0 are giving us. If we upgrade to 8.15.0, the concern is it'll break our systems by giving us a different formatting of the logs than expected from 7.13.0.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 10, 2024, 12:28pm UTC](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279/4 "2024-09-10T12:28:55Z")

</div>

You will need to test it.

It is not possible to guarantee compatibility with any system that is not from Elastic.

In overall the log didn't change, but some new fields may be added.
