# Auditbeat Equivalent for Elastic Agent

**URL:** https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171
**Category:** Beats
**Tags:** auditbeat
**Created:** [March 21, 2023, 2:10pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171 "2023-03-21T14:10:17Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![MakoWish](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MakoWish](https://discuss.elastic.co/u/MakoWish)
#### Post date: [March 21, 2023, 2:10pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/1 "2023-03-21T14:10:17Z")

</div>

When will there be an Auditbeat-equivalent Integration for Elastic Agent? We are trying to move exclusively to Elastic Agent, but the same monitoring done by Auditbeat is still not yet available that I can see.

Eric

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [March 21, 2023, 2:29pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/2 "2023-03-21T14:29:17Z")

</div>

There is some documentation on that topic. Have you seen [Migrate from Auditbeat to Elastic Agent | Fleet and Elastic Agent Guide [8.6] | Elastic](https://www.elastic.co/guide/en/fleet/current/migrate-auditbeat-to-agent.html)?

---

<div class="post-metadata">

### Author: ![MakoWish](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MakoWish](https://discuss.elastic.co/u/MakoWish)
#### Post date: [March 21, 2023, 2:52pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/3 "2023-03-21T14:52:12Z")

</div>

I have not seen that, but it does not quite appear to be a direct replacement for Auditbeat. Most everything says to use Endpoint or Osquery to gather the same data. We cannot deploy Endpoint, and Osquery is not real-time and quite clunky. Auditbeat was simple and did everything we needed. Has there been any discussion on creating an Auditbeat equivalent Integration?

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [March 21, 2023, 3:00pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/4 "2023-03-21T15:00:14Z")

</div>

The first line of the table posted in the link above is the Auditd module from Auditbeat.

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [March 21, 2023, 3:24pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/5 "2023-03-21T15:24:57Z")

</div>

> We cannot deploy Endpoint, and Osquery is not real-time and quite clunky.

The Endpoint (rebranded as Elastic Defend) and Osquery integrations are bundled into the Elastic Agent binary. So they will be there if you enable the features through Fleet and already have Elastic Agent installed.

The system.package dataset that's in Auditbeat is going to be exposed through Fleet. So those docs will be updated.

For `system.{process,socket,login}` I think the data from Elastic Defend is going to be better and it works on more operating systems than Auditbeat. For example Elastic Defend has better ways of getting process data by hooking into the kernel whereas Auditbeat gets process data by periodically grabbing a list of the processes.

And the [auditd](https://docs.elastic.co/integrations/auditd_manager) and [file integrity](https://docs.elastic.co/integrations/fim) parts are already exposed through Agent.

---

<div class="post-metadata">

### Author: ![MakoWish](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MakoWish](https://discuss.elastic.co/u/MakoWish)
#### Post date: [March 21, 2023, 6:08pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/6 "2023-03-21T18:08:27Z")

</div>

Hi Andrew,

We cannot deploy Elastic Defend because we already have a corporate anti-virus, and knowing my management, they will not allow two A/V to be installed side-by-side. I tested installing it in my lab environment, but disabled the Malware protections, and it does not appear to record login activity. The settings for Elastic Defend only show File, Network, and Process events for Linux.

Eric

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 18, 2023, 8:09pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171/7 "2023-04-18T20:09:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
