# Configure auditbeats to work with auditd

**URL:** <https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [November 20, 2023, 2:57pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544 "2023-11-20T14:57:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cdy5159](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdy5159/32/115812_2.png) [@cdy5159](https://discuss.elastic.co/u/cdy5159)\
**Post date:** [November 20, 2023, 2:57pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544/1 "2023-11-20T14:57:49Z")

</div>

My systems are required to have auditd operating and immutable. Can auditbeat be configured to work with immutable auditd? If so, how?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 20, 2023, 3:20pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544/2 "2023-11-20T15:20:47Z")

</div>

> [@cdy5159](#):
>
> My systems are required to have auditd operating

If you need to keep the auditd daemon running then I would recommend using Auditbeat with `socket_type: multicast` ([docs](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-auditd.html#_configuration_options_16)). In this mode it will receive a copy of the audit events from the kernel, and the `auditd` process can be left as is.

---

<div class="post-metadata">

**Author:** ![cdy5159](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdy5159/32/115812_2.png) [@cdy5159](https://discuss.elastic.co/u/cdy5159)\
**Post date:** [November 20, 2023, 3:34pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544/3 "2023-11-20T15:34:03Z")

</div>

That will work while auditd is set to immutable?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 20, 2023, 3:36pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544/4 "2023-11-20T15:36:48Z")

</div>

It should. It doesn't modify any kernel rules or set itself as the audit PID.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2023, 5:36pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544/5 "2023-12-18T17:36:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
