# Auditbeat showing logs that are filtered out

**URL:** <https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [January 22, 2019, 10:26am UTC](https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212 "2019-01-22T10:26:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![arhue](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@arhue](https://discuss.elastic.co/u/arhue)\
**Post date:** [January 22, 2019, 10:26am UTC](https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212/1 "2019-01-22T10:26:18Z")

</div>

Hello,

I'm trying to set log monitoring for servers but I can see logs that I have filtered out in Kibana. I want to it to only log entries where auid is between 2000 and 2099(including both). For that I have configured auditbeat with the following config.

Auditbeat config is here: [https://pastebin.com/NP7ZmuK9](https://pastebin.com/NP7ZmuK9)

But I can also see entries with auid as "0" or "unset" as shown in the image below:

 ![Screenshot%20from%202019-01-22%2015-53-23](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69544f1ece956755977d56b34584a5dd6ee3a9cb.png)

How can I make sure logs which have auid as unset or 0 are filtered out? All of my efforts in trial and error and Google searching/reading docs have been futile so far. Would really appreciate any help.

Thank you!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 27, 2019, 4:49pm UTC](https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212/2 "2019-01-27T16:49:08Z")

</div>

What does `auditbeat show auditd-rules` output?

How about something like

```auto
auditbeat.modules:
- module: auditd
  audit_rules: |
    -a never,exit -F auid<2000 -S all
    -a never,exit -F auid>2099 -S all
    -a exit,always -F arch=b64 -F euid=0 -S execve -k rootact
    -a exit,always -F arch=b32 -F euid=0 -S execve -k rootact
    -a exit,always -F arch=b64 -F euid>=1000 -S execve -k useract
    -a exit,always -F arch=b32 -F euid>=1000 -S execve -k useract

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2019, 4:49pm UTC](https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212/3 "2019-02-17T16:49:10Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
