# Multiple auditbeat file\_integrity module configurations

**URL:** https://discuss.elastic.co/t/multiple-auditbeat-file-integrity-module-configurations/259540
**Category:** Beats
**Tags:** auditbeat
**Created:** [December 24, 2020, 1:14am UTC](https://discuss.elastic.co/t/multiple-auditbeat-file-integrity-module-configurations/259540 "2020-12-24T01:14:02Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![p\_ansell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/p_ansell/32/61308_2.png) [@p\_ansell](https://discuss.elastic.co/u/p_ansell)
#### Post date: [December 24, 2020, 1:14am UTC](https://discuss.elastic.co/t/multiple-auditbeat-file-integrity-module-configurations/259540/1 "2020-12-24T01:14:02Z")

</div>

I have had issues in the past with the flexibility of the auditbeat file\_integrity module configuration. On one hand I want to monitor most changes under `/etc` and similar directories, but on another hand I also want to monitor a few very specific changes under `/home`.

I would like to benefit from the [new detection rule](https://github.com/elastic/detection-rules/issues/753) for alerting on changes to `~/.ssh/authorized_keys` files but currently I have chosen to instead monitor everything under `/etc` because it doesn't seem like there is a way to do both at one time using auditbeat.

Is there anyway of specifying a primary key for each auditbeat module configuration so that they don't conflict when there are multiple module configurations setup?

Basically I would like the following, but it doesn't seem to be supported right now:

```auto
    # Monitor system paths using exclusions
    - module: file_integrity
      paths:
      - /bin
      - /usr/bin
      - /sbin
      - /usr/sbin
      - /etc
      - /root

      exclude_files:
      - '(?i)\.sw[nop]$'
      - '~$'
      - '/\.git($|/)'

    # Monitor user directories using inclusions to only show .ssh file changes
    - module: file_integrity
      paths:
      - /home

      include_files:
      - '/\.ssh($|/)'

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 21, 2021, 3:14am UTC](https://discuss.elastic.co/t/multiple-auditbeat-file-integrity-module-configurations/259540/2 "2021-01-21T03:14:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
