# Configuring Auditbeat to only report modifications to files I want to monitor

**URL:** <https://discuss.elastic.co/t/configuring-auditbeat-to-only-report-modifications-to-files-i-want-to-monitor/150611>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [October 1, 2018, 8:23pm UTC](https://discuss.elastic.co/t/configuring-auditbeat-to-only-report-modifications-to-files-i-want-to-monitor/150611 "2018-10-01T20:23:45Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 2, 2018, 6:27pm UTC](https://discuss.elastic.co/t/configuring-auditbeat-to-only-report-modifications-to-files-i-want-to-monitor/150611/6 "2018-10-02T18:27:57Z")

</div>

Okay, this are audit events generated by other processes (pam, sudo, etc.), and they show up even if Auditbeat itself install no rules for them.

To filter them out, the suggestion is to install a drop processor. Have a look at this answer:

> [@Auditbeat event types](https://discuss.elastic.co/t/auditbeat-event-types/123966/2):
>
> Auditbeat subscribes to all events from the kernel's audit framework. Even if you configure no audit rules there are still events that get generated by other processes that publish audit events (like PAM, su, sudo). You can add a [processor](https://www.elastic.co/guide/en/beats/auditbeat/master/filtering-and-enhancing-data.html) to your configuration if you want to drop events. For example if you only wanted to receive events related to audit rules that you configured you could filter use auditbeat.modules: - module: auditd processors: - drop\_event.when.not.equals.event.category…

---

_[View the full topic](https://discuss.elastic.co/t/configuring-auditbeat-to-only-report-modifications-to-files-i-want-to-monitor/150611)._
