Filebeat module - auditd

(A G) #1


I am using auditd module in Filebeat to send the audit logs to Logstash. Do I still need to parse the audit logs in Logstash? When I sent the output to elasticsearch everything was working fine but whenswitched to Logstash it is not parsing the data.

is there a auditd module configuration file available just like syslog (link is below)?


(Carlos PĂ©rez Aradros) #2

Hi @charan.gandra,

I'm afraid Filebeat modules only work with Ingest node, if you are willing to use Logstash you can probably convert the pipeline from ingest to Logstash, as syntax is similar:

(A G) #3

Thank you.

(system) #4

