# Auditbeat auditd module vs. elastic agent auditd integration

**URL:** https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983
**Category:** Beats
**Tags:** auditbeat
**Created:** [May 25, 2021, 6:47pm UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983 "2021-05-25T18:47:27Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![lepepa9493](https://avatars.discourse-cdn.com/v4/letter/l/94ad74/32.png) [@lepepa9493](https://discuss.elastic.co/u/lepepa9493)
#### Post date: [May 25, 2021, 6:47pm UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983/1 "2021-05-25T18:47:27Z")

</div>

What is the difference between using the auditbeat auditd module and using the elastic agent auditd integration?

How can I use the elastic agent auditd integration with a custom auditd rules file or any other configuration option I can set in auditbeat.yml?

---

<div class="post-metadata">

### Author: ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)
#### Post date: [May 26, 2021, 6:59am UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983/2 "2021-05-26T06:59:47Z")

</div>

Did you look into documentation? [Auditd module | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-auditd.html)

> Although Filebeat is able to parse logs by using the `auditd` module, [Auditbeat](https://www.elastic.co/guide/en/beats/auditbeat/7.13/auditbeat-module-auditd.html) offers more advanced features for monitoring audit logs.

Speaking of elastic-agent, this is a bit different approach where you need to deploy an instance of elastic-agent and enroll with fleet in Kibana. Since then, you can change the auditd configuration using Kibana UI.

---

<div class="post-metadata">

### Author: ![lepepa9493](https://avatars.discourse-cdn.com/v4/letter/l/94ad74/32.png) [@lepepa9493](https://discuss.elastic.co/u/lepepa9493)
#### Post date: [May 26, 2021, 8:07am UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983/3 "2021-05-26T08:07:47Z")

</div>

Thanks for the explanation.

Do I get it right: The elastic-agent auditd integration is using the filebeat auditd module under the hood and not the auditbeat auditd module?

Is there a documentation of what the elastic-agent integrations are doing and what beats they replace? For example, it seems that the elastic-agent "Windows" integration is using auditbeat? But is it also installing sysmon?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 23, 2021, 10:08am UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983/4 "2021-06-23T10:08:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
