# Difference between (event.module: system - event.action: user\_login) AND (event.module: auditd - event.action: logged-in)

**URL:** <https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712>\
**Category:** SIEM\
**Tags:** ecs-elastic-common-schema, detection-rules\
**Created:** [July 27, 2021, 9:48am UTC](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712 "2021-07-27T09:48:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [July 27, 2021, 9:48am UTC](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712/1 "2021-07-27T09:48:34Z")

</div>

I have set on a host both packetbeat and auditbeat. I wanted to set a rule about login events but it confuses me a bit the separation between `event.module: system` and `event.module: auditd`.

At the SIEM overview there is not a very good explanation and categorization of which beat does a event.module belong and what about event.datasets.

Also my question came up when i say that there were two login events! First is `event.action: user_login` and the second is `event.action: logged-in `.

As someone that tries to catch and set a rule about login events that seems a bit confusing at least as of now that i haven't understand the relationship and the differences!

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [July 27, 2021, 11:46am UTC](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712/2 "2021-07-27T11:46:33Z")

</div>

Hi @panagiss thanks for your post.

Yes, it can be hard to remember which beats have modules, and which modules you've enabled.  
If you look at the `agent.type` field in the event, it will contain the name of the beat that produced the event, such as in this example, where we can clearly see that it was filebeat's system module that produced this event.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/3/13a4fe0cc2557aaf9ba575cd750836e4e1f2d2d7.jpeg)

However, one of the biggest advantages of using [Elastic Common Schema](https://www.elastic.co/guide/en/ecs/current/ecs-reference.html) (which all beats do), is that you don't necessarily need to track which beat or which module captured the login event, and you don't have to worry about which values of `event.action` are used. Instead, use the [ECS categorization fields](https://www.elastic.co/guide/en/ecs/current/ecs-category-field-values-reference.html#ecs-category-field-values-reference), `event.category` and `event.outcome` in your rule, to find desired authentication events.

For example in the rule creation dialog below we use `event.category:authentication AND event.outcome:success` to find all successful logins. The preview histogram shows events that would be detected by the rule.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e59838df51207fbc030b328c420ca0025ff5354.jpeg)

Please let us know if this helps.

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [July 27, 2021, 4:03pm UTC](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712/3 "2021-07-27T16:03:48Z")

</div>

Yeah thanks a lot. ECS fixes my problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2021, 4:03pm UTC](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712/4 "2021-08-24T16:03:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
