Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

Analysing Linux auditd anomalies with Auditbeat and machine learning

Blog post from Elastic

Post Details
Company
Date Published
Author
Michael Hirsch
Word Count
788
Company Posts That Month
36
Language
-
Hacker News Points
-
Post removed?
No
Summary

Auditbeat is a popular Beat that gathers data from the Linux audit framework to monitor processes on Linux systems, providing insights into security-related information, file integrity, and process data. Recently, machine learning job configurations have been introduced for the Auditbeat auditd module, enabling automatic detection of suspicious activities in server kernels or Docker containers. These analyses help identify anomalous user access or errant processes. Users can configure machine learning jobs that analyze rare process activity and high process rates, which are crucial for spotting potentially malicious activities hidden among common processes. The module offers dashboards, visualizations, and saved searches for both on-host and Docker environments, allowing for detailed investigations into identified anomalies, such as rare processes or unusual spikes in process activities, which might indicate security threats like flooding-style attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.