Auditd moduleedit

This module collects and parses logs from the audit daemon (auditd).

Compatibilityedit

This module was tested with logs from auditd on OSes like CentOS 6 and CentOS 7.

This module is not available for Windows.

Dashboardedit

This module comes with a sample dashboard showing an overview of the audit log data. You can build more specific dashboards that are tailored to the audit rules that you use on your systems.

./images/kibana-audit-auditd.png

Syslog fileset settingsedit

var.pathsedit

An array of paths where to look for the log files. If left empty, Filebeat will choose the paths depending on your operating systems.

Fieldsedit

For a description of each field in the metricset, see the exported fields section.