# Auditbeat handling of link and linkat syscalls

**URL:** <https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 13, 2025, 10:30pm UTC](https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868 "2025-03-13T22:30:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rafirs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafirs/32/141966_2.png) [@rafirs](https://discuss.elastic.co/u/rafirs)\
**Post date:** [March 13, 2025, 10:30pm UTC](https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868/1 "2025-03-13T22:30:00Z")

</div>

The hard link syscalls (link and linkat) do not seem to be configured properly and do not get the same treatment as other file calls.

If no one is currently working on it, I am happy to provide a pr to add them to go-libaudit/aucoalesce/normalizations.yaml

I've already tested a modified version with an extra block similar to symlink and the resulting output from auditbeat seems consistent and works well with my downstream pipeline.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 13, 2025, 11:07pm UTC](https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868/2 "2025-03-13T23:07:15Z")

</div>

Please do open a PR for elastic/go-libaudit. We probably don't have any test data with those syscalls so we should add some tests with the PR. Thanks.

---

<div class="post-metadata">

**Author:** ![rafirs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafirs/32/141966_2.png) [@rafirs](https://discuss.elastic.co/u/rafirs)\
**Post date:** [March 14, 2025, 7:44pm UTC](https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868/3 "2025-03-14T19:44:55Z")

</div>

> <https://github.com/elastic/go-libaudit/pull/177>
>
> These are the syscalls used for creating hard links.

I included some suggesting for testing, but did not add testing traces.

It looks like filebeat also has a syscall table that lacks these calls. I don't use that myself and have not examined the impact.
