# Auditbeat issue - custom audit rule not working

**URL:** <https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 13, 2019, 11:16am UTC](https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133 "2019-03-13T11:16:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![frankytamil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankytamil/32/41892_2.png) [@frankytamil](https://discuss.elastic.co/u/frankytamil)\
**Post date:** [March 13, 2019, 11:16am UTC](https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133/1 "2019-03-13T11:16:52Z")

</div>

I am new to ELK...

I have installed single node... Elasticsearch.. auditbeat and Kibana.... i can see documents in elasticsearch/kibana on default audits enabled bu auditbeat; not the one i enabled.

* * *

## [root@elk-testing-server auditbeat]# pwd /etc/auditbeat [root@elk-testing-server auditbeat]# grep -i testfolder auditbeat.yml -w /tmp/temp/testfolder -p rwxa -k testfolder\_change1 [root@elk-testing-server auditbeat]#

I see audit tag has some information in audit log; but this information not available via Kibana/Elasticsearch

[root@elk-testing-server auditbeat]# ausearch -k testfolder\_change1 | aureport -f -i

# File Report

# date time file syscall success exe auid event

===============================================

1. 03/13/2019 09:56:28 /tmp/temp/testfolder getxattr no /usr/bin/ls tamilanbu01114 4866
2. 03/13/2019 09:56:28 /tmp/temp/testfolder getxattr no /usr/bin/ls tamilanbu01114 4867
3. 03/13/2019 09:56:28 /tmp/temp/testfolder lgetxattr no /usr/bin/ls tamilanbu01114 4865
4. 03/13/2019 09:56:57 /tmp/temp/testfolder fchmodat yes /usr/bin/chmod tamilanbu01114 4868
5. 03/13/2019 09:57:18 /tmp/temp/testfolder fchmodat yes /usr/bin/chmod tamilanbu01114 4869
6. 03/13/2019 10:10:21 /tmp/temp/testfolder/ lgetxattr no /usr/bin/ls tamilanbu01114 4905
7. 03/13/2019 10:10:21 /tmp/temp/testfolder/ getxattr no /usr/bin/ls tamilanbu01114 4906
8. 03/13/2019 10:10:21 /tmp/temp/testfolder/ getxattr no /usr/bin/ls tamilanbu01114 4907
9. 03/13/2019 10:10:36 /tmp/temp/testfolder/ fchmodat yes /usr/bin/chmod tamilanbu01114 4908
10. 03/13/2019 10:10:40 /tmp/temp/testfolder/ lgetxattr no /usr/bin/ls tamilanbu01114 4909
11. 03/13/2019 10:10:40 /tmp/temp/testfolder/ getxattr no /usr/bin/ls tamilanbu01114 4910
12. 03/13/2019 10:10:40 /tmp/temp/testfolder/ getxattr no /usr/bin/ls tamilanbu01114 4911  
[root@elk-testing-server auditbeat]# curl localhost:9200/\_cat/indices?v  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
green open .kibana\_1 8fUBWMMqTH2mhUAcesPr2w 1 0 36 0 103.7kb 103.7kb  
yellow open sshd\_fail-2019.03 vk6cMATHTv-tLNmEF1Axrw 5 1 243 0 330kb 330kb  
yellow open auditbeat-6.6.2-2019.03.13 -kHJXMO9TKqi8gWHXPBCYg 3 1 5593 0 4.8mb 4.8mb  
[root@elk-testing-server auditbeat]#

* * *

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 15, 2019, 2:44pm UTC](https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133/2 "2019-03-15T14:44:54Z")

</div>

Can you please post the config file and the beginning of the auditbeat log file showing the first ~30s when it starts.

You are running both auditd and auditbeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 2:44pm UTC](https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133/3 "2019-04-05T14:44:54Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
