# Auditbeat dashboard in kibana shows empty results

**URL:** <https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782>\
**Category:** Beats\
**Tags:** docker, auditbeat\
**Created:** [September 6, 2022, 11:05am UTC](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782 "2022-09-06T11:05:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sargu\_Xcode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sargu_xcode/32/48484_2.png) [@Sargu\_Xcode](https://discuss.elastic.co/u/Sargu_Xcode)\
**Post date:** [September 6, 2022, 11:05am UTC](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782/1 "2022-09-06T11:05:21Z")

</div>

Hi All ,

I am trying to build a monitoring system for auditctl using auditbeat on Elasticsearch 7.8.1 and Kibana 7.8.1. Everything is successfully setup , including auditbeat. But the auditbeat dashboard seems empty when i attempt to view the auditd related info. I have verified auditbeat rules are set properly and it's index is running (hope am correct). Not sure what else to do. Kindly guide , thanks

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4908ab29bf3b08546ac1e63d6b6133ba12baf47.jpeg)  
 ![2](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df4461e5dd60acd8d5a3f47e9f7269f206c30128.jpeg)  
Uploading: 3.jpg...

 ![4](https://us1.discourse-cdn.com/elastic/original/3X/1/8/1898a654416bfd58b12a72b2bb69251b1a1f2124.jpeg)  
Uploading: 5.jpg...  
 ![6](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e195e3a91f2f0c4e7067725e23100a5ea4cf049c.jpeg)

auditbeat.yml config

```auto
[root@lxansidev02 elk]# grep -v "#" /etc/auditbeat/auditbeat.yml
auditbeat.modules:
- module: auditd
  audit_rule_files: ['${path.config}/audit.rules.d/*.conf']
  audit_rules: |
    -a always,exit -F arch=b32 -S all -F key=32bit-abi
    -a always,exit -F arch=b64 -S execve,execveat -k exec
    -w /etc/group -p wa -k identity
    -w /etc/passwd -p wrxa -k identity
    -w /etc/gshadow -p wa -k identity
- module: file_integrity
  paths:
  - /bin
  - /usr/bin
  - /sbin
  - /usr/sbin
  - /etc
- module: system
  datasets:
- module: system
  datasets:
  state.period: 12h
  user.detect_password_changes: true
  login.wtmp_file_pattern: /var/log/wtmp*
  login.btmp_file_pattern: /var/log/btmp*
  setup.template.settings:
  index.number_of_shards: 1
  setup.kibana:
  host: "localhost:5601"
  output.elasticsearch:
  hosts: ["localhost:9200"]
  username: "elastic"
  password: "admin"
  index: 'auditbeat'
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
setup.template.enabled: false

```

docker-compose.yml config

```auto
[root@lxansidev02 elk]# cat docker-compose.yml
version: '3'
services:
  elasticsearch:
    image: elasticsearch:7.8.1
    ports:
      - 9200:9200
    environment:
      discovery.type: 'single-node'
      xpack.security.enabled: 'true'
      ELASTIC_PASSWORD: 'admin'
  kibana:
    image: kibana:7.8.1
    volumes:
      - ./kibana.yml:/usr/share/kibana/config/kibana.yml
    ports:
      - 5601:5601

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2022, 11:05am UTC](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782/2 "2022-09-06T11:05:21Z")

</div>

Elasticsearch 7.8 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 7, 2022, 1:07am UTC](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782/3 "2022-09-07T01:07:56Z")

</div>

It looks like there are some 400k events from Auditbeat. I would check the Discovery tab and query for `event.module: auditd` and expand the time range to see if there are any events at all from auditd.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2022, 3:08am UTC](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782/4 "2022-10-05T03:08:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
