# What is Auditbeat audit syntax to exclude a process or path?

**URL:** <https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [January 22, 2022, 2:14pm UTC](https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117 "2022-01-22T14:14:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [January 22, 2022, 2:14pm UTC](https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117/1 "2022-01-22T14:14:36Z")

</div>

I have Auditbeat running with a bunch of CIS benchmark proposed auditd rules. One of my processes generates a bunch of false positive "time change" logs that I would like to filter out. `audit: type=1300 audit(1642859012.725:23957): arch=c000003e syscall=159 success=yes exit=5 a0=c000045ce0 a1=0 a2=0 a3=c00005dfc0 items=0 ppid=1 pid=848 auid=4294967295 uid=1001 gid=1001 euid=1001 suid=1001 fsuid=1001 egid=1001 sgid=1001 fsgid=1001 tty=(none) ses=4294967295 comm="node_exporter" exe="/home/tladmin/node_exporter" key="time-change"`  
I tried this config line:  
-a never,exclude -F path=/home/tladmin/node\_exporter -k exclude\_file  
but it fails with:  
`failed to interpret rule '-a never,exclude -F path=/home/tladmin/node_exporter -k exclude_file': failed to add filter '{2 path = /home/tladmin/node_exporter}': field 'path' cannot be used the exclude flag accessing 'auditbeat.modules.0' (source:'/etc/auditbeat/auditbeat.yml')`

So what is the secret syntax to doing an exclusion for a specific file path?

This syntax I used was taken from auditd examples ([How to exclude a file/directory from auditd rules – The Geek Diary](https://www.thegeekdiary.com/how-to-exclude-a-file-directory-from-auditd-rules/)) so if auditbeat used the same rules as auditd, then it should not complain about this syntax.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 22, 2022, 7:54pm UTC](https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117/2 "2022-01-22T19:54:56Z")

</div>

I think the way to exclude based on `exe` field would be:

`-a exclude,always -F exe=/home/tladmin/node_exporter`

Filtering on `exe` was added to the kernel in ~4.17, but I think Auditbeat needs to be updated to allow that.

> <https://github.com/linux-audit/audit-kernel/commit/29c1372d6a9b872acf479ba2744e4e7f043981c0>
>
> This patch removes the restriction of the AUDIT\_EXE field to only
> SYSCALL filter… and teaches audit\_filter to recognize this field.
> 
> This makes it possible to write rule lists such as:
> 
> auditctl -a exit,always \[some general rule\]
> # Filter out events with executable name /bin/exe1 or /bin/exe2:
> auditctl -a exclude,always -F exe=/bin/exe1
> auditctl -a exclude,always -F exe=/bin/exe2
> 
> See: https://github.com/linux-audit/audit-kernel/issues/54
> 
> Signed-off-by: Ondrej Mosnacek \<omosnace@redhat.com\>
> Reviewed-by: Richard Guy Briggs \<rgb@redhat.com\>
> Signed-off-by: Paul Moore \<paul@paul-moore.com\>

> <https://github.com/elastic/go-libaudit/blob/8189891e2a4812a7e3001c23bc5e38d0f7b303a2/rule/rule.go#L619-L625>

I found an existing issue that's related. [Update allowed fields with "exclude" flag · Issue #78 · elastic/go-libaudit · GitHub](https://github.com/elastic/go-libaudit/issues/78)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2022, 9:55pm UTC](https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117/3 "2022-02-19T21:55:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
