Auditbeat or Filebeat

Hi I just wondering what Auditbeat can audit what filebeat can't by logging

/var/log/audit/audit.log ?

we planned to install both auditbeat and filebeat on the same host but from my undersating filebeat also can get auditing info from audit.log file .

Best Regards.

Basically;

  • file integrity
  • the output from the auditd daemon

Filebeat can definitely extract some of the logs that Auditbeat processes, but it has preconfigured modules to structure them for the dashboards.

Thank you , what do you mean by "output from audit daemon" , the output from auditd is not written into audit.log file ?

Take a look at https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-auditd.html