Burga  
                (Burga)
               
                 
              
                  
                    August 25, 2020,  1:03pm
                   
                   
              1 
               
             
            
              Hi I just wondering what Auditbeat can audit what filebeat can't by  logging
/var/log/audit/audit.log ?
we planned to install  both auditbeat and filebeat on the same host but from my undersating filebeat also can get auditing info from audit.log file .
Best Regards.
             
            
               
               
               
            
            
           
          
            
              
                warkolm  
                (Mark Walkom)
               
              
                  
                    August 26, 2020,  4:40am
                   
                   
              2 
               
             
            
              Basically;
file integrity 
the output from the auditd daemon 
 
Filebeat can definitely extract some of the logs that Auditbeat processes, but it has preconfigured modules to structure them for the dashboards.
             
            
               
               
               
            
            
           
          
            
              
                Burga  
                (Burga)
               
              
                  
                    August 26, 2020,  5:12am
                   
                   
              3 
               
             
            
              Thank you , what do you mean by  "output from audit daemon" , the output from auditd is not written into audit.log file ?
             
            
               
               
               
            
            
           
          
            
              
                warkolm  
                (Mark Walkom)
               
              
                  
                    August 26, 2020,  5:22am
                   
                   
              4 
               
             
            
            
               
               
               
            
            
           
          
            
              
                system  
                (system)
                  Closed 
               
              
                  
                    September 23, 2020,  7:22am
                   
                   
              5 
               
             
            
              This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.