# Auditbeat output.file ignores permissions

**URL:** <https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [May 14, 2020, 12:15pm UTC](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637 "2020-05-14T12:15:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaclav](https://avatars.discourse-cdn.com/v4/letter/v/34f0e0/32.png) [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Post date:** [May 14, 2020, 12:15pm UTC](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637/1 "2020-05-14T12:15:31Z")

</div>

Hello,  
I found in latest auditbeat version 7.7.0 that auditbeat output file is created with permission 640 even if I set output file permission to 644.

I have this configuration in auditbeat.yml

```auto
output.file:
  path: "/var/auditbeat/logs"
  filename: auditbeat
  rotate_every_kb: 20000
  number_of_files: 2
  permissions: 0644

```

but output file have permission 640

```auto
ubuntu:/var/auditbeat/logs# ls -alF
total 184
drwxr-xr-x 2 root root 4096 May 14 05:12 ./
drwxr-xr-x 3 root root 4096 May 14 05:11 ../
-rw-r----- 1 root root 177590 May 14 05:12 auditbeat

```

Could it be bug ? It works in version 7.4.0

Thank you

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 14, 2020, 1:10pm UTC](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637/2 "2020-05-14T13:10:36Z")

</div>

Those permissions are pre-umask. This is why it becomes 0640. The logger creates the file with `0644`, but then the OS applies the processes umask to that mode value. The process has an 027 umask most likely.

I see there was a change in [https://github.com/elastic/beats/pull/14119](https://github.com/elastic/beats/pull/14119) to make the Beat set its own umask. So since the file output doesn't do an explicit `chmod` on the file you'll never get the configured `permissions`. This seems like a bug to me since users lose control of the permissions since they cannot control the process umask anymore.

---

<div class="post-metadata">

**Author:** ![vaclav](https://avatars.discourse-cdn.com/v4/letter/v/34f0e0/32.png) [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Post date:** [May 15, 2020, 7:38am UTC](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637/3 "2020-05-15T07:38:00Z")

</div>

than you Andrew, I will create bug

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 7:38am UTC](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637/4 "2020-06-05T07:38:05Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
