# Ubuntu system log parsing

**URL:** <https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293>\
**Category:** SIEM\
**Created:** [April 26, 2021, 7:20pm UTC](https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293 "2021-04-26T19:20:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guncixx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guncixx/32/87751_2.png) [@Guncixx](https://discuss.elastic.co/u/Guncixx)\
**Post date:** [April 26, 2021, 7:20pm UTC](https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293/1 "2021-04-26T19:20:30Z")

</div>

Hi,

I’m new to Elastic and trying to explore it’s security capabilities. For the testing purpose I set up some VMs and installed elastic agent to collect logs. I then tried to generate some successful and some unsuccessful login attempts to Ubuntu VM (locally, not with ash), unfortunately info from auth log or system log is not getting parsed. In elastic security event section I see message for failed logins but it’s not getting divided into separate fields (normalised) and because of that authentication rules are not firing also.  
I then uninstalled elastic agent and installed filebeat, because I thought it could be due to agents being still in beta, but same situation.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 27, 2021, 1:30am UTC](https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293/2 "2021-04-27T01:30:35Z")

</div>

Try auditbeat, it may have more of the events that you're looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2021, 1:30am UTC](https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293/3 "2021-05-25T01:30:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
