# Auditbeat: specified rules don't apply

**URL:** <https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [August 29, 2018, 11:23am UTC](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519 "2018-08-29T11:23:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guillaume\_Bettayeb](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@Guillaume\_Bettayeb](https://discuss.elastic.co/u/Guillaume_Bettayeb)\
**Post date:** [August 29, 2018, 11:23am UTC](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519/1 "2018-08-29T11:23:07Z")

</div>

Hi Everyone,

Not sure what I am doing wrong here but it seems like auditd does not apply the auditd rules I defined.

our Auditbeat uses both available modules, auditd and file\_integrity. and it looks like only the file\_integrity module sends its data to our Elasticsearch machine (we're not using logstash, straight from Elasticsearch to Kibana).

Our auditd rules list is quite extensive, it's based on this rule file : [https://gist.github.com/Neo23x0/9fe88c0c5979e017a389b90fd19ddfee](https://gist.github.com/Neo23x0/9fe88c0c5979e017a389b90fd19ddfee)

Here is what my module configuration in /etc/auditbeat/auditbeat.yml (CentOs 7) looks like:

#========================== Modules configuration =============================

auditbeat.modules:

- module: auditd

**skipping hundreds of lines**

```
-a always,exit -F arch=b64 -S mkdir,creat,link,symlink,mknod,mknodat,linkat,symlinkat -F exit=-EACCES -k file_creation

-a always,exit -F arch=b32 -S link,mkdir,symlink,mkdirat -F exit=-EPERM -k file_creation

-a always,exit -F arch=b64 -S mkdir,link,symlink,mkdirat -F exit=-EPERM -k file_creation

-a always,exit -F arch=b32 -S rename -S renameat -S truncate -S chmod -S setxattr -S lsetxattr -S removexattr -S lremovexattr -F exit=-EACCES -k file_modification

-a always,exit -F arch=b64 -S rename -S renameat -S truncate -S chmod -S setxattr -S lsetxattr -S removexattr -S lremovexattr -F exit=-EACCES -k file_modification

-a always,exit -F arch=b32 -S rename -S renameat -S truncate -S chmod -S setxattr -S lsetxattr -S removexattr -S lremovexattr -F exit=-EPERM -k file_modification

-a always,exit -F arch=b64 -S rename -S renameat -S truncate -S chmod -S setxattr -S lsetxattr -S removexattr -S lremovexattr -F exit=-EPERM -k file_modification

```

- module: file\_integrity

I also tried to point auditbeats to the auditd rules file 🙂  
audit\_rule\_files: ['/etc/audit/rules.d/audit.rules']  
but that doesn't seem to be working either. The rules are still ignored. If it wasn't ignored, I should see a lot more log entries in Elasticsearch as the rule file generates a lot of auditd logging.

What am I doing wrong ? or maybe I have too many rules nested under the auditd module?

Finally, it seems like auditdbeat is only sending its data to ES when I reload/restart the service...why is that? Is there some sort of "time-to-push" trigger that I need to configure so auditbeat keeps feeding ES with the newest auditbeat logs?

Yes, I run auditbeat with auditd completely stopped.

Thanks very much!

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [August 31, 2018, 11:42am UTC](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519/2 "2018-08-31T11:42:43Z")

</div>

Hi Guillaume, can you paste your Auditbeat log (if it doesn't contain any sensitive information)? I wonder if it contains any errors or warnings that could help us. You could also turn on debug logging using the `-d "auditd"` command line option.

What do you mean when you say that "auditdbeat is only sending its data to ES when I reload/restart the service"? I first thought you meant the rules are ignored and nothing is ever sent, or maybe sometimes it sends something and then it doesn't?

---

<div class="post-metadata">

**Author:** ![Guillaume\_Bettayeb](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@Guillaume\_Bettayeb](https://discuss.elastic.co/u/Guillaume_Bettayeb)\
**Post date:** [September 5, 2018, 11:28am UTC](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519/3 "2018-09-05T11:28:05Z")

</div>

Hello Christoph,

Thank you for getting back to me.

So a couple of things before I start; Please ignore when I said auditbeat only works when I restart it.. I was letting the auditd daemon running in the background. I didn't know it had to be stopped. I read it on this forum..maybe that information should be mentioned in some kind of info box in the official documentation?

Here is my auditbeat.yaml file: [https://pastebin.com/QZ2SF5Ke](https://pastebin.com/QZ2SF5Ke)

And here are the auditd logs file: [https://pastebin.com/AnnR9ub2](https://pastebin.com/AnnR9ub2)

I masked all sensitive information in the files.

Thank you very much for your help,

Guillaume

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2018, 11:28am UTC](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519/4 "2018-09-26T11:28:12Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
