# Auditbeat+logstash+splunk

**URL:** <https://discuss.elastic.co/t/auditbeat-logstash-splunk/290310>\
**Category:** Logstash\
**Created:** [November 26, 2021, 4:01pm UTC](https://discuss.elastic.co/t/auditbeat-logstash-splunk/290310 "2021-11-26T16:01:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![alejandromariani](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@alejandromariani](https://discuss.elastic.co/u/alejandromariani)\
**Post date:** [November 26, 2021, 4:01pm UTC](https://discuss.elastic.co/t/auditbeat-logstash-splunk/290310/1 "2021-11-26T16:01:53Z")

</div>

Good afternoon,

I am working on an integration between auditbeat + logstash + splunk

I have my auditbeat configuration from one of my nodes, pointing to my logstash

cat auditbeat.yml  
###################### Auditbeat Configuration #########################

auditbeat.modules:  
#FIM directories

- module: file\_integrity  
paths:
  - /bin
  - /usr/bin
  - /sbin
  - /usr/sbin
  - /etc
  - /var/lib/docker  
scan\_at\_start: true  
scan\_rate\_per\_sec: 50 MiB  
max\_file\_size: 100 MiB  
hash\_types: [sha1]  
recursive: false

#Elastic Security auditd events

- module: auditd  
resolve\_ids: true  
failure\_mode: silent  
backlog\_limit: 8196  
rate\_limit: 0  
include\_raw\_message: false  
include\_warnings: false  
audit\_rules: |  
-w /var/log/audit -k audit\_log\_access

#-------------------------- Logstash output ------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["xxxxxxxxxx:5044"]  
timeout: 30  
index: "auditbeat"  
tags: ["auditbeat", "cdc"]  
#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: critical, error, warning, info, debug

#logging.level: debug

and my logsthas send the events to splunk via a pipeline config.

cat 81\_output.splunk.conf  
input {  
pipeline { address =\> "output.splunk" }  
}

filter {  
mutate {  
add\_field =\> {  
"[@metadata][lsparams\_index\_suffix]" =\> ""  
}  
}  
}  
output {  
http {  
http\_method =\> "post"  
cacert =\> "/etc/logstash/ auth/cacert.pem"  
client\_cert =\> "/etc/logstash/ auth/server.der"  
client\_key =\> "/etc/logstash/ auth/privkey.pem"  
url =\> "[https://xxxxxxxxxxxxxx:8088/services/collector](https://xxxxxxxxxxxxxx:8088/services/collector)"  
headers =\> ["Authorization", "Splunk xxxxxxxxxxxx"]  
mapping =\> {  
"event" =\> "%{log}"  
}  
}  
}

I am getting the following error in logstash at startup

{"level":"ERROR","loggerName":"logstash.outputs.http","timeMillis":1637941666939,"thread":"[output.splunk]\>worker1","logEvent":{"message":"[HTTP Output Failure] Could not fetch URL","url":"[https://xxxxxxxxxx:8088/services/collector","method":{"metaClass":{"metaClass":{"metaClass":{"method":"post","message":"invalid](https://xxxxxxxxxx:8088/services/collector%22,%22method%22:%7B%22metaClass%22:%7B%22metaClass%22:%7B%22metaClass%22:%7B%22method%22:%22post%22,%22message%22:%22invalid) byte sequence in UTF-8","class":"ArgumentError","will\_retry":false}}}}}}

What could be the problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2021, 4:02pm UTC](https://discuss.elastic.co/t/auditbeat-logstash-splunk/290310/2 "2021-12-24T16:02:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
