# TTY logging decoding

**URL:** <https://discuss.elastic.co/t/tty-logging-decoding/150548>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [October 1, 2018, 10:11am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548 "2018-10-01T10:11:58Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 1, 2018, 10:11am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/1 "2018-10-01T10:11:58Z")

</div>

I did not try Auditbeat yet, but based on what I read so far it does not support decoding type=USER\_TTY or type=TTY audit records. Is this correct?

If it is correct, then this would be extremely disappointing. It would be extremely useful if it could decode the TTY logging keystrokes to be stored in an ELK stack system.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 1, 2018, 1:50pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/2 "2018-10-01T13:50:44Z")

</div>

Hi,

Auditbeat is perfectly capable of parsing TTY audit records.

May I ask where did you read that information?

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 7:04am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/3 "2018-10-02T07:04:22Z")

</div>

For testing I setup simple file output on logstash, an example of USER\_TTY record:

```
{"source":"/var/log/audit/audit.log","fileset":{"module":"auditd","name":"log"},"host":{"name":"host.example.com"},"@timestamp":"2018-10-02T06:58:50.847Z","off
set":19301726,"prospector":{"type":"log"},"@version":"1","tags":["beats_input_codec_plain_applied"],"input":{"type":"log"},"message":"node=host2.example.com type=TTY msg=audit(1538453437.764:15045): tty pid=15571 uid=0 auid=54162 ses=2477 major=136 minor=0 comm=\"bash\" data=6C73202D6C617472202F7661092E6C67097F7F7F6C6F67096E670909096909207C74616B7F696C0D","beat":{"version":"6.4.1","name":"host.example.com","hostname":"host.example.com"}}

```

The "data" field "6C732[...]" is not decoded to keystrokes.

Am I doing something wrong? I did not check a lot into the settings yet - these are on default settings with auditbeat exporting to logstash outputting to a file.

Edit: I do not see any relevant settings in auditbeat configuration.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 2, 2018, 9:34am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/4 "2018-10-02T09:34:29Z")

</div>

In my case, it decodes keystrokes successfully.

What is your Auditbeat, Kernel version and OS release?

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 9:43am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/5 "2018-10-02T09:43:16Z")

</div>

Thanks for helping with this problem!

Auditbeat is latest RPM, 6.4.1.  
Logstash is latest RPM, 6.4.1.

Auditbeat running on EL6 64-bit kernel 2.6.32-754.3.5 with audit 2.4.5-6 RPM.

I shall test with EL7 next

Edit:  
Tested with EL7, 64-bit kernel 3.10.0-862.11.6, audit 2.8.1-3 RPM.

The result is same, example output to logstash file with USER\_TTY data not decoded:  
`{"source":"/var/log/audit/audit.log","fileset":{"module":"auditd","name":"log"},"host":{"name":"host3.example.com"},"@timestamp":"2018-10-02T09:48:19.350Z","offset":4315449,"@version":"1","prospector":{"type":"log"},"tags":["beats_input_codec_plain_applied"],"input":{"type":"log"},"message":"node=host3.example.com type=USER_TTY msg=audit(1538473695.304:1199): pid=5535 uid=0 auid=5462 ses=141 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 **data=6C73202D6C61**","beat":{"version":"6.4.1","name":"host3.example.com","hostname":"host3.example.com"}}`

(the data=6C73202D6C61 should be decoded as "ls -la" somewhere...)

Edit: I guess I could use mutate filter and gsub each ASCII hex byte out of the "data" if there is seriously no other options...

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 2, 2018, 10:35am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/6 "2018-10-02T10:35:32Z")

</div>

I realised that the events you are pasting don't come from Auditbeat, but Filebeat. Those are log lines read from `/var/log/audit/audit.log` and not auditd events reported by Auditbeat.

I think you have Filebeat feeding logs to Elasticsearch too and got confused.

An Auditbeat event looks like this:

```auto
  "@timestamp": "2018-10-02T10:20:56.849Z",
  "@metadata": {
    "beat": "auditbeat",
    "type": "doc",
    "version": "7.0.0-alpha1"
  },
  "beat": {
    "name": "localhost.localdomain",
    "hostname": "localhost.localdomain",
    "version": "7.0.0-alpha1"
  },
  "event": {
    "category": "TTY",
    "type": "tty",
    "action": "typed",
    "module": "auditd"
  },
  "user": {
    "name_map": {
      "auid": "vagrant",
      "uid": "root"
    },
    "auid": "1000",
    "uid": "0"
  },
  "process": {
    "pid": "1680",
    "name": "yum"
  },
  "auditd": {
    "data": {
      "data": "y\n", # <- KEYSTROKES HERE
      "major": "136",
      "minor": "0"
    },
    "summary": {
      "how": "yum",
      "actor": {
        "primary": "vagrant",
        "secondary": "root"
      },
      "object": {
        "type": "keystrokes",
        "primary": "y\n"
      }
    },
    "sequence": 604,
    "result": "unknown",
    "session": "3"
  },
  "host": {
    "name": "localhost.localdomain"
  }
}

```

If you're using Kibana to inspect the events, make sure you have an auditbeat index pattern selected, not filebeat.

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 11:50am UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/7 "2018-10-02T11:50:02Z")

</div>

Interesting. On this machine Filebeat was installed only for Auditbeat usage. It outputs to logstash which outputs to a file - in a different pipeline from everything else and it is the only beats input on the logstash.

The config is similarly very simple on the client;  
output.logstash:  
hosts: ["192.0.2.1:5044"]

```
filebeat.config.modules:
 path: ${path.config}/modules.d/*.yml
 reload.enabled: false

setup.template.settings:
 index.number_of_shards: 3

```

The file modules.d/auditd.yml is default and there is no other configuration on client:  
- module: auditd  
log:  
enabled: true

And pipeline on logstash:  
input {  
beats {  
port =\> 5044  
}  
}  
output {  
file {  
path =\> "/opt/logstash/audit/%{host}/%{+YYYY-MM-dd}.log"  
}  
}

Based on what you say it sounds like I cannot output to logstash, I should output directly to Elasticsearch. I will try that next then.

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 12:20pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/8 "2018-10-02T12:20:12Z")

</div>

I was trying to avoid running the "filebeat 'setup intial environment'" since it requires the ingest-geoip (which I do not care about), and forces me to use a specific template and creates a ton of dashboards I do not care about.

I did it anyways, and now there is the index "filebeat-6.4.1-2018.10.02". The mappings include "auditd" section but there is no "type:" "keystrokes" in there.

I see you are running 7.0.0 alpha. Are you sure it is not a feature of 7.0?

Edit: there is also a grok error.  
`Provided Grok expressions do not match field value: [node=host.example.com type=USER_TTY msg=audit(1538482400.901:121392): pid=26742 uid=0 auid=5462 ses=15978 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 data=6C2020(rest cut out)]`

Edit: the only index created was the aforementioned filebeat index, no index for auditbeat to be seen anywhere.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 2, 2018, 12:43pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/9 "2018-10-02T12:43:46Z")

</div>

There's a misunderstanding here.

What you're using is Filebeat with the `auditd` module. This doesn't decode TTY.

What you want to use is [Auditbeat](https://www.elastic.co/products/beats/auditbeat), which is a different Beat altogether, and does TTY data decoding.

This has nothing to do with outputting to Logstash or directly to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 12:51pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/10 "2018-10-02T12:51:19Z")

</div>

Duh. Well that makes sense totally. Thanks.

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 2:13pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/11 "2018-10-02T14:13:56Z")

</div>

Working great now that this "small" misunderstanding was corrected. Sorry to waste your time.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 2, 2018, 4:26pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/12 "2018-10-02T16:26:10Z")

</div>

Don't worry, no waste at all 🙂

It also took me a long time to realise the events you were sharing didn't belong to auditbeat.

---

<div class="post-metadata">

**Author:** ![bluiks](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Post date:** [October 2, 2018, 4:31pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/13 "2018-10-02T16:31:26Z")

</div>

It looks very good so far - deployed to a few dozen machines for testing. Much better than auditd+audisp-remote to centralize audit logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2018, 4:31pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548/14 "2018-10-23T16:31:31Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
