# Auditd module + file access = some paths are hex-encoded

**URL:** <https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 22, 2018, 12:06am UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090 "2018-03-22T00:06:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ceekay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ceekay/32/5687_2.png) [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Post date:** [March 22, 2018, 12:06am UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/1 "2018-03-22T00:06:46Z")

</div>

We're looking to track all file access on a shared volume, and are running the following config:

- module: auditd  
audit\_rules: |  
-w /share/path\_a -p rwa  
-w /share/path\_b -p rwa  
-w /share/path\_c -p rwa

This seems to work fine, except that some events have hex-encoded values for `auditd.summary.object.primary` and `file.path` instead of plain text. I can't understand where this hex-encoded value is coming from, but it's making the results quite unusable. These are unique events, and if I filter these out in Kibana with `NOT file.path:\[0-9A-F]*\` then I miss file system events that have occurred.

Example doc: [https://gist.github.com/ceeeekay/19365fa135be6bf039ebb589c242a68a](https://gist.github.com/ceeeekay/19365fa135be6bf039ebb589c242a68a)

Any help please?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 22, 2018, 12:04pm UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/2 "2018-03-22T12:04:19Z")

</div>

That looks like something we can fix. Can you add `include_raw_message: true` to your auditd module configuration temporarily ([docs](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-auditd.html)) and share the event again just like you did.

Then we'll add the messages to the [testdata](https://github.com/elastic/go-libaudit/tree/master/auparse/testdata) to create a test case for this. Then in the code make sure that we have [hex decoding](https://github.com/elastic/go-libaudit/blob/ffe11fbcf126128805ee08aa6f568d230feb4bf4/auparse/auparse.go#L321) applied to the right fields.

---

<div class="post-metadata">

**Author:** ![ceekay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ceekay/32/5687_2.png) [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Post date:** [March 22, 2018, 11:28pm UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/3 "2018-03-22T23:28:51Z")

</div>

@andrewkroh here's the gist of one document with the paths redacted and re-encoded:

> <https://gist.github.com/ceeeekay/688fbb11f24e9c2d9b4260ad4dfdd7a7>

There are other documents with different `event.action` values. Do you need those as well?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 23, 2018, 1:45pm UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/4 "2018-03-23T13:45:02Z")

</div>

Thanks for the event data.

I think by fixing decoding in all `type=PATH` messages this should be covered so I don't think we need the other events with different `event.action` values.

I opened [https://github.com/elastic/go-libaudit/issues/20](https://github.com/elastic/go-libaudit/issues/20) for this. You can subscribe to the issue in Github for updates.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 23, 2018, 1:49pm UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/5 "2018-03-23T13:49:13Z")

</div>

One more question: What OS (usually `cat /etc/*release`) and kernel version (`uname -a`) is this event from?

---

<div class="post-metadata">

**Author:** ![ceekay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ceekay/32/5687_2.png) [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Post date:** [March 23, 2018, 9:09pm UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/6 "2018-03-23T21:09:38Z")

</div>

@andrewkroh This one is `Ubuntu 14.04.5 LTS / 3.13.0-143-generic`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:17am UTC](https://discuss.elastic.co/t/auditd-module-file-access-some-paths-are-hex-encoded/125090/7 "2022-11-04T05:17:56Z")

</div>


