# Security audit index shows tons of fake failed authentications/min (5.1.1) - SOLVED

**URL:** <https://discuss.elastic.co/t/security-audit-index-shows-tons-of-fake-failed-authentications-min-5-1-1-solved/73811>\
**Category:** Elasticsearch\
**Created:** [February 3, 2017, 8:33am UTC](https://discuss.elastic.co/t/security-audit-index-shows-tons-of-fake-failed-authentications-min-5-1-1-solved/73811 "2017-02-03T08:33:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vsmirnov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vsmirnov/32/34694_2.png) [@vsmirnov](https://discuss.elastic.co/u/vsmirnov)\
**Post date:** [February 3, 2017, 8:33am UTC](https://discuss.elastic.co/t/security-audit-index-shows-tons-of-fake-failed-authentications-min-5-1-1-solved/73811/1 "2017-02-03T08:33:14Z")

</div>

Hi all,

I have x-pack security audit enabled with file and index output. After I set up TLS for inter-node, Kibana and Filebeat communications, security\_audit\_log\* indexes started being filled by hundreds of authentication\_failed events for different users (personal accounts of Kibana users, filebeat's etc), whereas ES \*\_access.log files show only rare real failed logins. There're no such failed authentications and even no events with the same timestamp in logfiles. And these simply don't look real - I definitely don't fail to login by my personal account 100s of times per minute.

All those indexed failed authentication events happen only on 1 of 3 nodes (not currently master) where Kibana is running and pointed to and filebeat is sending logs to. Failures occur only during periods of user activity - e.g. auth failures for my personal account during work hours and filebeat's all the time (live log stream). For personal accounts failures node address and origin address are the same (that one node producing this docs), for filebeat's - origin address is filebeat host's IP.

Realms config is default (so should be native+file).

Environment ES + Kibana + Filebeat, all V5.1 on RHEL7.

Has anyone experienced this?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 6, 2017, 12:11am UTC](https://discuss.elastic.co/t/security-audit-index-shows-tons-of-fake-failed-authentications-min-5-1-1-solved/73811/2 "2017-02-06T00:11:50Z")

</div>

I suspect these are actually `realm_authentication_failed` events rather than regular `authentication_failed` events. See [https://www.elastic.co/guide/en/x-pack/5.1/auditing.html](https://www.elastic.co/guide/en/x-pack/5.1/auditing.html)

If you are using default configuration, then the order tried will be

- reserved
- native
- file

The reserved realm handles builtin users like the `elastic` superuser.

So, regular _native_ users _always_ generate a `realm_authentication_failed` event when they log in because they are not authenticated by the reserved realm, and _file_ users will generate two events.

It sounds like you are not interested in the `realm_authentication_failed` and should put it in the `.exclude` setting for your [audit log configuration](https://www.elastic.co/guide/en/x-pack/5.1/auditing.html#audit-index)

**Note** : You didn't indicate which patch version of 5.1 you are running. There was a bug that was [fixed in 5.1.2](https://www.elastic.co/guide/en/x-pack/5.1/xpack-release-notes.html) that would cause `realm_authentication_failed` event to be written to the index-audit-log as if they were `authentication_failed` events. So if you're not on 5.1.2 you ought to look at upgrading.

---

<div class="post-metadata">

**Author:** ![vsmirnov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vsmirnov/32/34694_2.png) [@vsmirnov](https://discuss.elastic.co/u/vsmirnov)\
**Post date:** [February 6, 2017, 3:31am UTC](https://discuss.elastic.co/t/security-audit-index-shows-tons-of-fake-failed-authentications-min-5-1-1-solved/73811/3 "2017-02-06T03:31:45Z")

</div>

Thanks a lot, Tim!  
The bug is exactly what was happening. Just upgraded to 5.2.0 (was 5.1.1) and excluded the event from logging. Happy now! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2017, 3:32am UTC](https://discuss.elastic.co/t/security-audit-index-shows-tons-of-fake-failed-authentications-min-5-1-1-solved/73811/4 "2017-03-06T03:32:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
