I installed Elasticsearch and Auditbeat service version 8.15.2 for Ubuntu Server 22.04. After host reboot, auditbeat inactive and not send log to ELK node.
service auditbeat status
○ auditbeat.service - Audit the activities of users and processes on your system.
Loaded: loaded (/lib/systemd/system/auditbeat.service; disabled; vendor pre>
Active: inactive (dead)
Docs: https://www.elastic.co/beats/auditbeat
Yeah, i forget it. Auditbeat actived, then i reboot host and auditbeat inactive.
Auditbeat not work normally, miss log for mornitoring system until i restart it manually. This is so inconvenient because i have many hosts.
So i should have a shell executing active Auditbeat whenever host reboot/ shutdown or configure of auditbeat can perform it to i not start it manually?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.