# Dec 2nd, 2019: \[EN\]\[Auditbeat\] Monitoring Linux Command Execution

**URL:** <https://discuss.elastic.co/t/dec-2nd-2019-en-auditbeat-monitoring-linux-command-execution/209125>\
**Category:** Advent Calendar\
**Created:** [December 2, 2019, 8:00am UTC](https://discuss.elastic.co/t/dec-2nd-2019-en-auditbeat-monitoring-linux-command-execution/209125 "2019-12-02T08:00:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![json](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/json/32/4125_2.png) [@json](https://discuss.elastic.co/u/json)\
**Post date:** [December 2, 2019, 8:00am UTC](https://discuss.elastic.co/t/dec-2nd-2019-en-auditbeat-monitoring-linux-command-execution/209125/1 "2019-12-02T08:00:00Z")

</div>

The Auditbeat Auditd module can be used to capture all shell commands executed on system for all users. Monitoring shell commands is often desired on servers where end user shell activity is normally minimal.

This example was assembled on CentOS Linux 7.6 using the Auditbeat 7.4.2 RPM package and Elastic Stack 7.4.2 on the [Elasticsearch Service (ESS)](https://www.elastic.co/products/elasticsearch/service).

You can start your own ESS deployment 14-day trial through [this page](https://www.elastic.co/cloud/elasticsearch-service/signup), for free.

Most of the steps detailed in this article are applicable on a self-hosted Elasticsearch & Kibana deployment.

## Disable System Auditd

The system `auditd` daemon will interfere with the Auditbeat Auditd module and must be disabled.

Stop `auditd`:

```auto
service auditd stop

```

Disable the service:

```auto
systemctl disable auditd.service

```

If running Auditd is required while using the Auditbeat Auditd module, consider setting `socket_type: multicast` if the kernel version is 3.16 or newer. The default is `unicast`. See the configuration options section of the [documentation](https://www.elastic.co/guide/en/beats/auditbeat/master/auditbeat-module-auditd.html#_configuration_options_14) for more information.

## Configure Auditbeat

My Auditbeat daemon ships event data to an Elasticsearch Service (ESS) cluster. See the [Configuring Auditbeat](https://www.elastic.co/guide/en/beats/auditbeat/master/configuring-howto-auditbeat.html) documentation for more details. Auditbeat settings `cloud.id` and `cloud.auth` are required to get the example working ([documentation](https://www.elastic.co/guide/en/beats/auditbeat/master/configure-cloud-id.html)).

Edit `/etc/auditbeat/auditbeat.yml`:

```auto
cloud.id: <your_cloud_id>
cloud.auth: ingest_user:password

```

In case you want to send the data to your Elasticsearch cluster (e.g. a local instance), please check this [documentation page](https://www.elastic.co/guide/en/beats/auditbeat/master/elasticsearch-output.html).

### Auditbeat Auditd Module Rules

The Auditd module subscribes to the kernel to receive system events. Rules are defined to capture these events and are in the same format used by the Linux `auditctl` utility (more details [here](https://linux.die.net/man/8/auditctl)).

`/etc/auditbeat/audit.rules.d/rules.conf`:

```auto
-a exit,always -F arch=b64 -F euid=0 -S execve -k root_acct
-a exit,always -F arch=b32 -F euid=0 -S execve -k root_acct
-a exit,always -F arch=b64 -F euid>=1000 -S execve -k user_acct
-a exit,always -F arch=b32 -F euid>=1000 -S execve -k user_acct

```

- `euid` is the effective user id. `0` will capture all activities for the root user and `>=1000` for all other users with a uid of 1000 or higher.
- `-k <key>` is used to assign an arbitrary "key" to the event and it will show up in the `tags` field. It can be used in Kibana to filter and categorize events.

### Auditbeat Setup Command

Run Auditbeat setup to load index templates, ingest node pipelines, the index filecycle policy and the Kibana dashboards.

```auto
auditbeat -e setup

```

In case you're not using ESS, we invite you to check the [documentation](https://www.elastic.co/guide/en/beats/auditbeat/current/setup-kibana-endpoint.html) in order to setup the Kibana endpoint

## Start Auditbeat

```auto
systemctl start auditbeat

```

List enabled rules:

```auto
auditbeat show auditd-rules
-a never,exit -S all -F pid=23617
-a always,exit -F arch=b64 -S execve -F euid=root -F key=root_acct
-a always,exit -F arch=b32 -S execve -F euid=root -F key=root_acct
-a always,exit -F arch=b64 -S execve -F euid>=vagrant -F key=user_acct
-a always,exit -F arch=b32 -S execve -F euid>=vagrant -F key=user_acct

```

## Watch for Data

Issue some shell commands like `whoami`, `ls`, and `lsblk` as a user and monitor Kibana Discover for new events.

 ![shell_logging_1](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c32e0bfa65e66d5b4bb9de765f4cd00adae466f.png)

- Kibana shown with `user.name`, `process.executable`, `process.args` and `tags` fields selected.
- Filter is `user.name: root` and `auditd.data.syscall: execve`.
- Data refresh is every second.

## TTY Auditing

The Auditbeat Auditd module can also pick up TTY events as they occur on the system. Configure the `system-auth` PAM configuration file to enable TTY audting. Only root TTY events will be logged in real-time. User events are normally buffered until `exit`. TTY auditing is required to capture builtin shell commands like `pwd`, `test`, etc.

Append the following to `/etc/pam.d/system-auth` to enable auditing for all users (more details about `pam_tty_audit` can be found [here](https://linux.die.net/man/8/pam_tty_audit)):

```auto
session required pam_tty_audit.so enable=*

```

### Test

```auto
$ sudo su -
Last login: Fri Nov 22 23:43:00 UTC 2019 on pts/0
$ helllloooo there!
-bash: helllloooo: command not found
$ exit

```

#### Kibana Discover

 ![shell_logging_2](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f00d7b4e17671c801b5718bf690743df16eb2a0.png)

## Final thoughts

Auditbeat is also able to:

- Send events when a file is changed (created, updated, or deleted) on disk thanks to the `file_integrity` module ([documentation](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html))
- Send metrics regarding the system thanks to the `system` module ([documentation](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-system.html))

The Auditbeat documentation is available at [this link](https://www.elastic.co/guide/en/beats/auditbeat/current/index.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:34am UTC](https://discuss.elastic.co/t/dec-2nd-2019-en-auditbeat-monitoring-linux-command-execution/209125/2 "2022-11-04T07:34:33Z")

</div>


