# Auditbeat with Redis

**URL:** <https://discuss.elastic.co/t/auditbeat-with-redis/122336>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 2, 2018, 10:32pm UTC](https://discuss.elastic.co/t/auditbeat-with-redis/122336 "2018-03-02T22:32:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![run4fun3](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@run4fun3](https://discuss.elastic.co/u/run4fun3)\
**Post date:** [March 2, 2018, 10:32pm UTC](https://discuss.elastic.co/t/auditbeat-with-redis/122336/1 "2018-03-02T22:32:08Z")

</div>

I'm wanting to setup auditbeat to do file integrity monitoring and want to send it to my already existing ELK stack. Right now I have logstash going to redis then logstash pulls the logs down and sends them to elasticsearch. so Logstash -\> Redis -\> Logstash -\>Elastic search -\>kibana. I have got audit beats working by outputing directly to elasticsearch however i want to run it though Redis. Auditbeat -\> Redis -\> Elasticsearch -\>Kibana. I see there is a redis output option but when I send it to redis i don't get any logs in showing in kibana. is there a part i need to add to logstash when pulling down from redis that's separate from the rest of my logs?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 9, 2018, 2:02pm UTC](https://discuss.elastic.co/t/auditbeat-with-redis/122336/2 "2018-03-09T14:02:00Z")

</div>

Can you show us your Filebeat and Logstash configs?

---

<div class="post-metadata">

**Author:** ![run4fun3](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@run4fun3](https://discuss.elastic.co/u/run4fun3)\
**Post date:** [March 9, 2018, 4:17pm UTC](https://discuss.elastic.co/t/auditbeat-with-redis/122336/3 "2018-03-09T16:17:01Z")

</div>

Thanks for the reply I actually got it figured out. I had to add the key to the Redis output. then I pulled it off Redis with Logstash using the same key and added the index name because I didn't have this key I was sending them to the Logstash index.

output.redis:  
enabled: true  
hosts: ["IP"]  
port: 5002  
key: auditbeat  
datatype: list

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:15am UTC](https://discuss.elastic.co/t/auditbeat-with-redis/122336/4 "2022-11-04T05:15:51Z")

</div>


