# Auditbeat does not log all commands executed by users

**URL:** <https://discuss.elastic.co/t/auditbeat-does-not-log-all-commands-executed-by-users/359088>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [May 8, 2024, 5:14pm UTC](https://discuss.elastic.co/t/auditbeat-does-not-log-all-commands-executed-by-users/359088 "2024-05-08T17:14:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Claudio\_Ract\_Costa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudio_ract_costa/32/26095_2.png) [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Post date:** [May 8, 2024, 5:14pm UTC](https://discuss.elastic.co/t/auditbeat-does-not-log-all-commands-executed-by-users/359088/1 "2024-05-08T17:14:58Z")

</div>

Hi All,

How can I configure auditbeat to log all commands executed by users ?

I am asking it because when i execute "echo test" command, it is not logged by auditbeat, but when i execute "/usr/bin/echo test" command, it is logged successfully

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 8, 2024, 6:28pm UTC](https://discuss.elastic.co/t/auditbeat-does-not-log-all-commands-executed-by-users/359088/2 "2024-05-08T18:28:08Z")

</div>

`echo test` is using a "shell built-in" (like env, export, etc.) and those do not generate process events because they are not new Linux processes. It's something that is happening within the existing shell process as opposed to executing an `execve` system call to launch a new process.

If you want to monitor what is being entered into a shell then one option is to enable the Linux pam\_tty\_audit module. The causes auditd events to be emitted as keystrokes are entered into the terminal.

- [https://linux.die.net/man/8/pam\_tty\_audit](https://linux.die.net/man/8/pam_tty_audit)
- [7.9.&nbsp;Configuring PAM for Auditing Red Hat Enterprise Linux 6 | Red Hat Customer Portal](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing)
