# File integrity module not capturing user data

**URL:** <https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 27, 2019, 11:01am UTC](https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099 "2019-03-27T11:01:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![arunpmohan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arunpmohan/32/69467_2.png) [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Post date:** [March 27, 2019, 11:01am UTC](https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099/1 "2019-03-27T11:01:21Z")

</div>

Iam using Auditbeat's file integrity module to listen to a few folders.  
Now, following is the sample of the file\_integrity module's output file

```
 {
              "osName": "ubuntu",
              "osCategory": "linux",
              "@timestamp": "2019-03-02T03:28:39.809Z",
              "file": {
                "inode": "779302",
                "owner": "root",
                "mode": "0644",
                "path": "/etc/auditbeat/auditbeat.yml",
                "uid": 0,
                "gid": 0,
                "size": 33258,
                "ctime": "2019-03-02T03:28:22.706Z",
                "mtime": "2019-03-02T03:28:22.682Z",
                "type": "file",
                "group": "root"
              },
              "osVersion": 16,
              "beatName": "auditbeat",
              "@version": "1",
              "beat": {
                "name": "k8720asd",
                "hostname": "k8720asd",
                "version": "6.5.4"
              },
              "host": {
                "name": "k8720asd"
              },
              "event": {
                "action": [
                  "updated",
                  "attributes_modified"
                ],
                "module": "file_integrity"
              },
              "device": [
                "k8720asd"
              ],
              "hash": {
                "sha1": "9962115130ee05a05cd8d236c94d8b038d773e43"
              }
            } 

```

In the above document, there is no information on which user performed the above operations.  
Is there anyway that we can get this using the file\_integrity module?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 1, 2019, 2:49pm UTC](https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099/2 "2019-04-01T14:49:31Z")

</div>

The file integrity monitoring (FIM) module doesn't provide an audit trail for who made the change. This is because the Linux API (inotify) doesn't provide the data. If you need the user you can setup a rule with the auditd module to generate an event when a file is written.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2019, 2:49pm UTC](https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099/3 "2019-04-22T14:49:42Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
