# SSH Access Rule

**URL:** <https://discuss.elastic.co/t/ssh-access-rule/235647>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [June 3, 2020, 10:53pm UTC](https://discuss.elastic.co/t/ssh-access-rule/235647 "2020-06-03T22:53:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alsheh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alsheh/32/36799_2.png) [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Post date:** [June 3, 2020, 10:53pm UTC](https://discuss.elastic.co/t/ssh-access-rule/235647/1 "2020-06-03T22:53:39Z")

</div>

To detect SSH access, I'm using the rule below:

```auto
## External access (warning: these can be expensive to audit).
-a always,exit -F arch=b64 -S accept,bind,connect -F key=external-access

```

This is generating a lot of events so I'm interested to fine tune the rule to catch the SSH events only. Ideally, this can be done without dropping the events via the auditbeat processor to make it less expensive on the host to monitor. Any guidance on how that can be done?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2020, 10:56pm UTC](https://discuss.elastic.co/t/ssh-access-rule/235647/2 "2020-06-03T22:56:37Z")

</div>

Are you asking a question here? It's not really clear given you have only posted two lines of text from somewhere.

---

<div class="post-metadata">

**Author:** ![Alsheh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alsheh/32/36799_2.png) [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Post date:** [June 3, 2020, 10:57pm UTC](https://discuss.elastic.co/t/ssh-access-rule/235647/3 "2020-06-03T22:57:59Z")

</div>

sorry, I accidentally posted before finishing typing. I've updated my original post.

---

<div class="post-metadata">

**Author:** ![Alsheh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alsheh/32/36799_2.png) [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Post date:** [June 13, 2020, 3:28am UTC](https://discuss.elastic.co/t/ssh-access-rule/235647/4 "2020-06-13T03:28:34Z")

</div>

Solved by using Filebeat system module which collects logs from `/var/log/auth.log`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2020, 3:28am UTC](https://discuss.elastic.co/t/ssh-access-rule/235647/5 "2020-07-04T03:28:34Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
