{"id":3517,"date":"2019-07-04T21:38:35","date_gmt":"2019-07-04T18:38:35","guid":{"rendered":"https:\/\/kifarunix.com\/?p=3517"},"modified":"2019-07-04T21:38:36","modified_gmt":"2019-07-04T18:38:36","slug":"install-and-configure-elastic-auditbeat-on-ubuntu-18-04","status":"publish","type":"post","link":"https:\/\/kifarunix.com\/install-and-configure-elastic-auditbeat-on-ubuntu-18-04\/","title":{"rendered":"Install and Configure Elastic Auditbeat on Ubuntu 18.04"},"content":{"rendered":"\n

In this guide, we are going to learn how to install and configure Elastic Auditbeat<\/a> on Ubuntu 18.04. Auditbeat is a lightweight data shipper that is used to collect audit events for users and system processes. It can also be used to detect changes to critical files, like binaries and configuration files, and identify potential security policy violations.<\/p>\n\n\n\n

Auditbeat is an Elastic Beat and hence, in order to use it, you need to install Elastic stack. See our guide on how to install Elastic Stack 7 on Ubuntu 18.04 below;<\/p>\n\n\n\n

Install Elastic Stack 7 on Ubuntu 18.04\/Debian 9.8<\/a><\/p>\n\n\n\n

Install and Configure Elastic Auditbeat on Ubuntu 18.04<\/h2>\n\n\n\n

Install Auditbeat on Ubuntu 18.04<\/h3>\n\n\n\n

Auditbeat can be install from Elastic Repos or directly using the DEB binary.<\/p>\n\n\n\n

To install from Elastic repos;<\/p>\n\n\n\n