# Linux\_anomalous\_process\_all\_hosts\_ecs apparently not only covering Linux, but full auditbeat

**URL:** <https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519>\
**Category:** SIEM\
**Tags:** elastic-stack-machine-learning\
**Created:** [January 5, 2022, 10:24am UTC](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519 "2022-01-05T10:24:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 5, 2022, 10:24am UTC](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519/1 "2022-01-05T10:24:21Z")

</div>

Hello,

I was a bit surprised to see the "Anomalous Process For a Linux Population" SIEM rule trigger for Windows hosts.

After some investigation, I noticed there is no filter for `host.os.type` or `host.os.family` or sth similar. The anomaly job `linux_anomalous_process_all_hosts_ecs` looks at anomalous processes for Auditbeat in general, so also on Windows hosts...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aa1ab1eaefd9d8cfd9a8f94dbf3920d1e8f17465.png)

It seems to me that this confusion can be solved by adding a filter on `host.os.family` in the `linux_anomalous_process_all_hosts_ecs` job...

So changing the default config:

```auto
{
  "bool": {
    "filter": [
      {
        "terms": {
          "event.action": [
            "process_started",
            "executed"
          ]
        }
      },
      {
        "term": {
          "agent.type": "auditbeat"
        }
      }
    ],
    "must_not": [
      {
        "bool": {
          "should": [
            {
              "term": {
                "user.name": "jenkins-worker"
              }
            },
            {
              "term": {
                "user.name": "jenkins-user"
              }
            },
            {
              "term": {
                "user.name": "jenkins"
              }
            },
            {
              "wildcard": {
                "process.name": {
                  "wildcard": "jenkins*"
                }
              }
            }
          ],
          "minimum_should_match": 1
        }
      }
    ]
  }
}

```

To:

```auto
{
  "bool": {
    "filter": [
      {
        "terms": {
          "event.action": [
            "process_started",
            "executed"
          ]
        }
      },
      {
        "term": {
          "agent.type": "auditbeat"
        }
      },
      {
        "term": {
          "host.os.type": "linux"
        }
      }
    ],
    "must_not": [
      {
        "bool": {
          "should": [
            {
              "term": {
                "user.name": "jenkins-worker"
              }
            },
            {
              "term": {
                "user.name": "jenkins-user"
              }
            },
            {
              "term": {
                "user.name": "jenkins"
              }
            },
            {
              "wildcard": {
                "process.name": {
                  "wildcard": "jenkins*"
                }
              }
            }
          ],
          "minimum_should_match": 1
        }
      }
    ]
  }
}

```

Should do the trick?

The ML job `rare_process_by_host_linux_ecs` for the SIEM rule `Unusual Process For a Linux Host` has the same issue..

The ML job `suspicious_login_activity` for the SIEM rule `Unusual Login Activity` has `signal.rule.tag` Linux (not Windows..), but also triggers on Windows events... Imho this job should be called `suspicious_linux_login_activity` and `"host.os.type": "linux"` should be added in the query..

There might be others..

Willem

---

<div class="post-metadata">

**Author:** ![Craig\_Chamberlain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_chamberlain/32/70079_2.png) [@Craig\_Chamberlain](https://discuss.elastic.co/u/Craig_Chamberlain)\
**Post date:** [January 5, 2022, 7:28pm UTC](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519/2 "2022-01-05T19:28:48Z")

</div>

Hello, so there are newer versions of the Linux ML jobs in 7.11 and later in a module named Security: Linux. The jobs in this module test for operating system type. The new version of this particular job is the one named v2\_linux\_anomalous\_process\_all\_hosts\_ecs.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 6, 2022, 8:35am UTC](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519/3 "2022-01-06T08:35:45Z")

</div>

Thanks for your answer @Craig_Chamberlain

I have found some 'new' v2 jobs with better queries including os type..

`v2_linux_anomalous_process_all_hosts_ecs`  
`v2_rare_process_by_host_linux_ecs`

But I could not immediately find a v2 version of the ML job `suspicious_login_activity` for the SIEM rule `Unusual Login Activity`? This one also applies to Windows hosts and the SIEM rule also only has a Linux tag.. ([Unusual Login Activity | Elastic Security Solution [7.16] | Elastic](https://www.elastic.co/guide/en/security/current/unusual-login-activity.html))

Something else I noticed is that the `v2_linux_anomalous_network_port_activity_ecs` only queries events where `event.type` equals `start`. The result is only auditd events are captured and not `system.socket`. In the Auditbeat `system.socket` dataset, `event.type` equals `connection`...

Is there a reason only `event.type:start` events are included in this ML job and not `event.type:connection`?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2022, 8:36am UTC](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519/4 "2022-02-03T08:36:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
