Burga
(Burga)
August 25, 2020, 1:03pm
1
Hi I just wondering what Auditbeat can audit what filebeat can't by logging
/var/log/audit/audit.log ?
we planned to install both auditbeat and filebeat on the same host but from my undersating filebeat also can get auditing info from audit.log file .
Best Regards.
warkolm
(Mark Walkom)
August 26, 2020, 4:40am
2
Basically;
file integrity
the output from the auditd daemon
Filebeat can definitely extract some of the logs that Auditbeat processes, but it has preconfigured modules to structure them for the dashboards.
Burga
(Burga)
August 26, 2020, 5:12am
3
Thank you , what do you mean by "output from audit daemon" , the output from auditd is not written into audit.log file ?
warkolm
(Mark Walkom)
August 26, 2020, 5:22am
4
system
(system)
Closed
September 23, 2020, 7:22am
5
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.