# Elastic Agent Integration: File Integrity Monitoring (FIM)

**URL:** https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448
**Category:** Endpoint Security
**Created:** [November 29, 2021, 3:17pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448 "2021-11-29T15:17:59Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![morgan.atwood](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@morgan.atwood](https://discuss.elastic.co/u/morgan.atwood)
#### Post date: [November 29, 2021, 3:17pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448/1 "2021-11-29T15:17:59Z")

</div>

Will the elastic agent/endpoint eventually have file integrity monitoring like Auditbeat in the future? Looking for options to replace TrendMicro but it looks like I'll have to use auditbeat or osquery with the elastic agent to fully replace it.

Thanks!

---

<div class="post-metadata">

### Author: ![Yamin\_Tian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yamin_tian/32/80373_2.png) [@Yamin\_Tian](https://discuss.elastic.co/u/Yamin_Tian)
#### Post date: [November 29, 2021, 7:23pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448/2 "2021-11-29T19:23:12Z")

</div>

Elastic Endpoint provides the capability of monitor file changes such as modify/rename/delete and event on the activities, as well as other preventative capabilities when files are accessed.

---

<div class="post-metadata">

### Author: ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)
#### Post date: [December 1, 2021, 10:25am UTC](https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448/3 "2021-12-01T10:25:47Z")

</div>

Thanks @Yamin_Tian.

@morgan.atwood just to add to Yamin's point above, while our Endpoint Security integration does cover FIM use cases, we are also in the process of migrating Auditbeat functionality, including FIM, to Elastic Agent. I can't share timelines at the moment, but it is certainly a focus area for us.

I'd love to discuss your FIM requirements in more detail, and understand how you're using Trend Micro FIM currently - will drop you a note to schedule some time or discuss offline.

---

<div class="post-metadata">

### Author: ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)
#### Post date: [December 8, 2021, 3:10am UTC](https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448/4 "2021-12-08T03:10:10Z")

</div>

How can I capture this the FIM in the Elastic Agent in work? My organization is doing Fedramp audit right now, and I need to provide evidence of this somehow?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 5, 2022, 3:10am UTC](https://discuss.elastic.co/t/elastic-agent-integration-file-integrity-monitoring-fim/290448/5 "2022-01-05T03:10:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
