# Auditbeat event types

**URL:** <https://discuss.elastic.co/t/auditbeat-event-types/123966>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 14, 2018, 5:47pm UTC](https://discuss.elastic.co/t/auditbeat-event-types/123966 "2018-03-14T17:47:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![grants](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grants/32/117040_2.png) [@grants](https://discuss.elastic.co/u/grants)\
**Post date:** [March 14, 2018, 5:47pm UTC](https://discuss.elastic.co/t/auditbeat-event-types/123966/1 "2018-03-14T17:47:43Z")

</div>

Is there a list of auditbeat event types and categories? It seems that auditbeat is logging authentication events when I don't see anything besides 1 single rule in my auditbeat.yml config file so I'm curious if there is ways to turn on and off specific categories and a comprehensive list of what is available. I don't see any documentation that shows "user-login" events are coming from when they contain no tags, meanwhile there are events with my tag with a category of "audit-rule".

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 14, 2018, 6:10pm UTC](https://discuss.elastic.co/t/auditbeat-event-types/123966/2 "2018-03-14T18:10:14Z")

</div>

Auditbeat subscribes to all events from the kernel's audit framework. Even if you configure no audit rules there are still events that get generated by other processes that publish audit events (like PAM, su, sudo).

You can add a [processor](https://www.elastic.co/guide/en/beats/auditbeat/master/filtering-and-enhancing-data.html) to your configuration if you want to drop events. For example if you only wanted to receive events related to audit rules that you configured you could filter use

```auto
auditbeat.modules:
- module: auditd
  processors:
  - drop_event.when.not.equals.event.category: "audit-rule"
  audit_rules: |
    # my audit rules

```

Linux has a [list](https://github.com/linux-audit/audit-documentation/blob/master/specs/messages/message-dictionary.csv) of audit event types. These map to `event.type` in Auditbeat. The value is lowercased and the leading `AUDIT_` is removed.

The `event.category` field comes from Auditbeat. It sets the category based on the `event.type` value. You can see the list of categories in the code at [https://github.com/elastic/go-libaudit/blob/bc29b128d4099fb834634afb535241f1608fb2f0/aucoalesce/event\_type.go#L45-L63](https://github.com/elastic/go-libaudit/blob/bc29b128d4099fb834634afb535241f1608fb2f0/aucoalesce/event_type.go#L45-L63).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:17am UTC](https://discuss.elastic.co/t/auditbeat-event-types/123966/3 "2022-11-04T05:17:07Z")

</div>


