# Problems in using auditbeat to collect user commands

**URL:** <https://discuss.elastic.co/t/problems-in-using-auditbeat-to-collect-user-commands/241380>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [July 16, 2020, 3:14am UTC](https://discuss.elastic.co/t/problems-in-using-auditbeat-to-collect-user-commands/241380 "2020-07-16T03:14:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![lovelysoda](https://avatars.discourse-cdn.com/v4/letter/l/d6d6ee/32.png) [@lovelysoda](https://discuss.elastic.co/u/lovelysoda)\
**Post date:** [July 16, 2020, 3:14am UTC](https://discuss.elastic.co/t/problems-in-using-auditbeat-to-collect-user-commands/241380/1 "2020-07-16T03:14:30Z")

</div>

HI，  
About collecting user commands。  
I think of two solutions，If there is any misunderstanding, please correct it。  
First，we can use pam\_tty\_audit , configure the `system-auth` PAM configuration file to enable TTY audting . But there's one bad thing ，the records of non-root users are written to the buffer, and they will not appear in a record until the buffer is full or the session exits. Can't view the records of uploaded es very well. Because it belongs to TTY.  
Second，we can use audit rule，"-a always,exit -F arch=b64 -S execve,execveat -k exec". But there's one bad thing,audit will miss shell built-ins（alias，echo）.  
It was thought of using bash's environment variables to record all the commands used by users, but we imagine that if an attacker bypasses the environment variables or does not apply bash, it will not be recorded.  
Do you have any solutions to the above problems? Or other schemes record all user commands.

centos 7.8 , auditbeat 7.5.1, kernel 3.10.0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2020, 3:14am UTC](https://discuss.elastic.co/t/problems-in-using-auditbeat-to-collect-user-commands/241380/2 "2020-08-13T03:14:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
