# Not getting TTY translations in Auditbeat 6.7

**URL:** <https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [July 22, 2019, 4:50pm UTC](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684 "2019-07-22T16:50:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hobapolis](https://avatars.discourse-cdn.com/v4/letter/h/ea666f/32.png) [@hobapolis](https://discuss.elastic.co/u/hobapolis)\
**Post date:** [July 22, 2019, 4:50pm UTC](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684/1 "2019-07-22T16:50:06Z")

</div>

Hello!

I'm trying to get auditbeat to translate my TTY. I have the basics set up properly and I'm, for now, using the default rules that come out of the box with auditbeat.

My `/etc/pam.d/common-session` file ends with

```auto
session required pam_tty_audit.so enable=*

```

What I'd like to see is something along the lines of what `/var/log/audit.log` spits out:

```auto
type=TTY msg=audit(1563826068.496:30191): tty pid=22321 uid=0 auid=1059801645 ses=17 major=136 minor=1 comm="vim" data=1B5B323B32521B5B3E303B39353B30636A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6A6B6B6B6B6B6B6B6B6B6B6B6B3A710D

```

It seems like this is do-able as another user had a somewhat-related question last year:

> [@TTY logging decoding](https://discuss.elastic.co/t/tty-logging-decoding/150548/6):
>
> I realised that the events you are pasting don't come from Auditbeat, but Filebeat. Those are log lines read from /var/log/audit/audit.log and not auditd events reported by Auditbeat. I think you have Filebeat feeding logs to Elasticsearch too and got confused. An Auditbeat event looks like this: "@timestamp": "2018-10-02T10:20:56.849Z", "@metadata": { "beat": "auditbeat", "type": "doc", "version": "7.0.0-alpha1" }, "beat": { "name": "localhost.localdomain", "hostn…

Specifically this line:

` "data": "y\n", # <- KEYSTROKES HERE`

I cannot seem to get this in any of my fields. I'm happy to post my rules but they are simply the default ones that come with Auditbeat.

Would love any help/suggestions.

FWIW I'm using AWS Elasticsearch 6.7

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 22, 2019, 10:20pm UTC](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684/2 "2019-07-22T22:20:10Z")

</div>

Can you confirm that you see the keystrokes in:

```auto
# aureport --tty

```

If not, then there's a misconfiguration in your tty logging setup.

---

<div class="post-metadata">

**Author:** ![hobapolis](https://avatars.discourse-cdn.com/v4/letter/h/ea666f/32.png) [@hobapolis](https://discuss.elastic.co/u/hobapolis)\
**Post date:** [July 23, 2019, 12:09pm UTC](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684/3 "2019-07-23T12:09:25Z")

</div>

i wasn't aware that `auditd` had to be installed on the instance running auditbeat in order to get TTY translation working.

that being said there is loads of entries running that command. i don't see any of them reflected in my elasticsearch cluster via kibana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2019, 12:09pm UTC](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684/4 "2019-08-13T12:09:26Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
