@cwurm Thanks for reply! Here you have the results:
Ad. 1:
auditbeat:
modules:
- module: system
output:
elasticsearch:
hosts:
- http://<elasticsearch_ip>:9200
path:
config: /opt/elastic/auditbeat
data: /opt/elastic/auditbeat/data
home: /opt/elastic/auditbeat
logs: /opt/elastic/auditbeat/logs
processors:
- add_host_metadata: null
Ad. 2
/opt/elastic/auditbeat # ./auditbeat -e -d "*"
2019-04-02T11:53:58.239+0200 INFO instance/beat.go:616 Home path: [/opt/elastic/auditbeat] Config path: [/opt/elastic/auditbeat] Data path: [/opt/elastic/auditbeat/data] Logs path: [/opt/elastic/auditbeat/logs]
2019-04-02T11:53:58.239+0200 DEBUG [beat] instance/beat.go:653 Beat metadata path: /opt/elastic/auditbeat/data/meta.json
2019-04-02T11:53:58.239+0200 INFO instance/beat.go:623 Beat UUID: c11c97e6-4f1d-4a8a-9451-591898594b33
2019-04-02T11:53:58.239+0200 DEBUG [seccomp] seccomp/seccomp.go:99 No seccomp policy is defined
2019-04-02T11:53:58.239+0200 INFO [beat] instance/beat.go:936 Beat info {"system_info": {"beat": {"path": {"config": "/opt/elastic/auditbeat", "data": "/opt/elastic/auditbeat/data", "home": "/opt/elastic/auditbeat", "logs": "/opt/elastic/auditbeat/logs"}, "type": "auditbeat", "uuid": "c11c97e6-4f1d-4a8a-9451-591898594b33"}}}
2019-04-02T11:53:58.239+0200 INFO [beat] instance/beat.go:945 Build info {"system_info": {"build": {"commit": "b002f33ddc9bf7602dc7dbc45910bfd3f2c5df5a", "libbeat": "6.6.1", "time": "2019-02-12T14:27:01.000Z", "version": "6.6.1"}}}
2019-04-02T11:53:58.239+0200 INFO [beat] instance/beat.go:948 Go runtime info {"system_info": {"go": {"os":"linux","arch":"ppc64le","max_procs":8,"version":"go1.11.5"}}}
2019-04-02T11:53:58.240+0200 INFO [beat] instance/beat.go:952 Host info {"system_info": {"host": {"architecture":"ppc64le","boot_time":"2018-12-10T13:08:18+01:00","containerized":false,"name":"********","ip":["127.0.0.1/8","::1/128","********/**","fe80::f8fc:31ff:fe79:b520/64"],"kernel_version":"4.4.155-94.50-default","mac":["**********"],"os":{"family":"suse","platform":"sles","name":"SLES","version":"12-SP3","major":12,"minor":0,"patch":0},"timezone":"CEST","timezone_offset_sec":7200,"id":"476d3ed2557640bbe9bf9b255c0e46e7"}}}
2019-04-02T11:53:58.240+0200 INFO [beat] instance/beat.go:981 Process info {"system_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac_override","dac_read_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux_immutable","net_bind_service","net_broadcast","net_admin","net_raw","ipc_lock","ipc_owner","sys_module","sys_rawio","sys_chroot","sys_ptrace","sys_pacct","sys_admin","sys_boot","sys_nice","sys_resource","sys_time","sys_tty_config","mknod","lease","audit_write","audit_control","setfcap","mac_override","mac_admin","syslog","wake_alarm","block_suspend","audit_read"],"effective":["chown","dac_override","dac_read_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux_immutable","net_bind_service","net_broadcast","net_admin","net_raw","ipc_lock","ipc_owner","sys_module","sys_rawio","sys_chroot","sys_ptrace","sys_pacct","sys_admin","sys_boot","sys_nice","sys_resource","sys_time","sys_tty_config","mknod","lease","audit_write","audit_control","setfcap","mac_override","mac_admin","syslog","wake_alarm","block_suspend","audit_read"],"bounding":["chown","dac_override","dac_read_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux_immutable","net_bind_service","net_broadcast","net_admin","net_raw","ipc_lock","ipc_owner","sys_module","sys_rawio","sys_chroot","sys_ptrace","sys_pacct","sys_admin","sys_boot","sys_nice","sys_resource","sys_time","sys_tty_config","mknod","lease","audit_write","audit_control","setfcap","mac_override","mac_admin","syslog","wake_alarm","block_suspend","audit_read"],"ambient":null}, "cwd": "/data/elastic/auditbeat", "exe": "/data/elastic/auditbeat/auditbeat", "name": "auditbeat", "pid": 24632, "ppid": 21322, "seccomp": {"mode":"disabled"}, "start_time": "2019-04-02T11:53:57.440+0200"}}}
2019-04-02T11:53:58.240+0200 INFO instance/beat.go:281 Setup Beat: auditbeat; Version: 6.6.1
2019-04-02T11:53:58.240+0200 DEBUG [beat] instance/beat.go:302 Initializing output plugins
2019-04-02T11:53:58.241+0200 DEBUG [processors] processors/processor.go:66 Processors: add_host_metadata=[netinfo.enabled=[false], cache.ttl=[5m0s]]
2019-04-02T11:53:58.241+0200 INFO elasticsearch/client.go:165 Elasticsearch url: http://145.218.225.21:9200
2019-04-02T11:53:58.241+0200 DEBUG [publish] pipeline/consumer.go:137 start pipeline event consumer
2019-04-02T11:53:58.241+0200 INFO [publisher] pipeline/module.go:110 Beat name: ********
2019-04-02T11:53:58.241+0200 DEBUG [modules] beater/metricbeat.go:103 Register [ModuleFactory:[], MetricSetFactory:[auditd/auditd, file_integrity/file]]
2019-04-02T11:53:58.241+0200 DEBUG [processors] processors/processor.go:66 Processors:
2019-04-02T11:53:58.241+0200 INFO instance/beat.go:360 auditbeat stopped.
2019-04-02T11:53:58.241+0200 ERROR instance/beat.go:911 Exiting: 1 error: no metricsets configured for module 'system'
Exiting: 1 error: no metricsets configured for module 'system'
Ad 3. I've tried with a config without dataset definition but the result is exactly the same as above.