# Auditbeat - SIEM

**URL:** <https://discuss.elastic.co/t/auditbeat-siem/187853>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [June 27, 2019, 1:44pm UTC](https://discuss.elastic.co/t/auditbeat-siem/187853 "2019-06-27T13:44:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cob](https://avatars.discourse-cdn.com/v4/letter/c/e9bcb4/32.png) [@cob](https://discuss.elastic.co/u/cob)\
**Post date:** [June 27, 2019, 1:44pm UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/1 "2019-06-27T13:44:32Z")

</div>

Hello All,

I'm currently playing with and testing out the SIEM plugin. However, as soon as I feed it Auditbeat data, I seem to get a message error which I'm not really sure about. I thought that the SIEM would work natively with Auditbeat data. However, the (huge) error I'm receiving is:

> [illegal\_argument\_exception] Fielddata is disabled on text fields by default. Set fielddata=true on [host.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead. (and) [illegal\_argument\_exception] Fielddata is disabled on text fields by default. Set fielddata=true on [host.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory.

I've tried looking around for similar issues but I'm not sure if those older issues relate to my current issue.

Thanks!

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [June 27, 2019, 2:23pm UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/2 "2019-06-27T14:23:16Z")

</div>

Hi @cob, it looks like you need to set up the Auditbeat index. Have you run `./auditbeat setup` before running Auditbeat itself?

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [June 27, 2019, 2:36pm UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/3 "2019-06-27T14:36:57Z")

</div>

Sorry, actually the error should not have happened even without `./auditbeat setup` (which is still important to run).

What seems to have happened is that it did not load the correct index template, and so the `host.name` field is not a `keyword` field. How did you set up Auditbeat? Which version is it? Did you modify the Auditbeat configuration? Do you know if there was an `auditbeat-*` index or index template already present in Elasticsearch before? Can you provide the full configuration and log of Auditbeat starting (with `./auditbeat -e`)?

If you can (i.e. if you don't have any historical Auditbeat data you care about) the easiest thing to do would be to ensure that there are no Auditbeat indexes or templates around (run `DELETE auditbeat-*` and `DELETE _template/auditbeat-*` - please ONLY do this if you don't care about the existing Auditbeat data).

---

<div class="post-metadata">

**Author:** ![cob](https://avatars.discourse-cdn.com/v4/letter/c/e9bcb4/32.png) [@cob](https://discuss.elastic.co/u/cob)\
**Post date:** [June 28, 2019, 8:39am UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/4 "2019-06-28T08:39:25Z")

</div>

I deleted my old message as I figure out was the issue. I had to run the setup on the local machine for it to create the proper mappings/indexes/indices and now it works like a charm. Now I can start changing stuff and learn more about it.

Thanks for directing me in the good direction!

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [June 28, 2019, 12:05pm UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/5 "2019-06-28T12:05:17Z")

</div>

@cob Great!

For everyone else who might be reading this: Logstash creates `text` fields by default, which do not allow aggregations. So you have to set `manage_template => false` in the Logstash config for the Elasticsearch output, and load the index template from Beats using e.g. `./auditbeat setup` (with `output.elasticsearch` enabled, then switch it off and enable `output.logstash` when running without `setup`).

---

<div class="post-metadata">

**Author:** ![proxx](https://avatars.discourse-cdn.com/v4/letter/p/3d9bf3/32.png) [@proxx](https://discuss.elastic.co/u/proxx)\
**Post date:** [July 12, 2019, 12:46am UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/6 "2019-07-12T00:46:12Z")

</div>

Thanks cwurum. Had the same problem too, got i resolved

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2019, 12:46am UTC](https://discuss.elastic.co/t/auditbeat-siem/187853/7 "2019-08-02T00:46:19Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
