# SIEM - Any overlap between filbeat ingesting syslog, auditlog, authlog and auditbeat (with auditd, system and FI modules)?

**URL:** <https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235>\
**Category:** SIEM\
**Created:** [December 2, 2019, 7:45pm UTC](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235 "2019-12-02T19:45:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vsubrama](https://avatars.discourse-cdn.com/v4/letter/v/e9c0ed/32.png) [@vsubrama](https://discuss.elastic.co/u/vsubrama)\
**Post date:** [December 2, 2019, 7:45pm UTC](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235/1 "2019-12-02T19:45:36Z")

</div>

We are currently ingesting syslog, auditlog, authlog from our ubuntu systems via filebeat to Elasticsearch 7.4.2 as a part of build our SIEM. We are planning to add auditbeat with auditd, system and file integrity modules. By doing this are we double ingesting something now (such as auditlog) or are these two independent things?

---

<div class="post-metadata">

**Author:** ![nwed](https://avatars.discourse-cdn.com/v4/letter/n/dbc845/32.png) [@nwed](https://discuss.elastic.co/u/nwed)\
**Post date:** [December 4, 2019, 9:20pm UTC](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235/2 "2019-12-04T21:20:38Z")

</div>

There certainly is overlap with auditlog and auditd. If you look at just the auditlog, you will find it's rather hard to consume and make use of in a forensic investigation. The enriched version of audit with auditbeat, is the way to go. Depending on your rules, you may see overlap with secure, and auth as well. You need to identify if those logs are actually useful to an analyst, many of them have UID's. Depending on your auth, those UID's could be common (ldap) or different on each host.

---

<div class="post-metadata">

**Author:** ![vsubrama](https://avatars.discourse-cdn.com/v4/letter/v/e9c0ed/32.png) [@vsubrama](https://discuss.elastic.co/u/vsubrama)\
**Post date:** [December 5, 2019, 10:26pm UTC](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235/3 "2019-12-05T22:26:14Z")

</div>

Thanks a lot for the reply. Appreciate it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 10:26pm UTC](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235/4 "2019-12-26T22:26:17Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
