# Community\_ID

**URL:** https://discuss.elastic.co/t/community-id/183636
**Category:** Beats
**Tags:** auditbeat
**Created:** [May 31, 2019, 1:12am UTC](https://discuss.elastic.co/t/community-id/183636 "2019-05-31T01:12:40Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![james007](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@james007](https://discuss.elastic.co/u/james007)
#### Post date: [May 31, 2019, 1:12am UTC](https://discuss.elastic.co/t/community-id/183636/1 "2019-05-31T01:12:41Z")

</div>

Hello, I have audit beat v8.0.0 running on CentOS 7.6.1810. I am able to run auditbeat, and I added

```auto
  - community_id:
      fields:
        source_ip: my_source_ip
        source_port: my_source_port
        destination_ip: my_dest_ip
        destination_port: my_dest_port
        transport: proto
        icmp_type: my_icmp_type
        icmp_code: my_icmp_code
      target: network.community_id

```

to the processors section of auditbeats.yml. But when I check the log for the community\_id value it isn't there. Any ideas?

Thanks,

---

<div class="post-metadata">

### Author: ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)
#### Post date: [May 31, 2019, 11:57am UTC](https://discuss.elastic.co/t/community-id/183636/2 "2019-05-31T11:57:35Z")

</div>

Can you share your full configuration and a sample event in JSON that you believe should've been enriched?

---

<div class="post-metadata">

### Author: ![james007](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@james007](https://discuss.elastic.co/u/james007)
#### Post date: [May 31, 2019, 12:16pm UTC](https://discuss.elastic.co/t/community-id/183636/3 "2019-05-31T12:16:04Z")

</div>

I used the example configuration and added the information to the processors section. I am still testing so I start auditbeat by:

./auditbeat -c auditbeat.yml -e -d "\*"

###################### Auditbeat Configuration Example #########################

# This is an example configuration file highlighting only the most common

# options. The auditbeat.reference.yml file from the same directory contains all

# the supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [https://www.elastic.co/guide/en/beats/auditbeat/index.html](https://www.elastic.co/guide/en/beats/auditbeat/index.html)

#========================== Modules configuration =============================  
auditbeat.modules:

- module: auditd

- module: file\_integrity  
paths:

#==================== Elasticsearch template setting ==========================  
setup.template.settings:  
index.number\_of\_shards: 1  
#index.codec: best\_compression  
#\_source.enabled: false

#================================ General =====================================

# The name of the shipper that publishes the network data. It can be used to group

# all the transactions sent by a single shipper in the web interface.

#name:

# The tags of the shipper are included in their own field with each

# transaction published.

#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the

# output.

#fields:

# env: staging

#============================== Dashboards =====================================

# These settings control loading the sample dashboards to the Kibana index. Loading

# the dashboards is disabled by default and can be enabled either by setting the

# options here or by using the `setup` command.

#setup.dashboards.enabled: false

# The URL from where to download the dashboards archive. By default this URL

# has a value which is computed based on the Beat name and version. For released

# versions, this URL points to the dashboard archive on the [artifacts.elastic.co](http://artifacts.elastic.co)

# website.

#setup.dashboards.url:

#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.

# This requires a Kibana endpoint configuration.

setup.kibana:

# Kibana Host

# Scheme and port can be left out and will be set to the default (http and 5601)

# In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)

# IPv6 addresses should always be defined as: https://[2001:db8::1]:5601

#host: "localhost:5601"

# Kibana Space ID

# ID of the Kibana Space into which the dashboards should be loaded. By default,

# the Default Space will be used.

#space.id:

#============================= Elastic Cloud ==================================

# These settings simplify using auditbeat with the Elastic Cloud ([https://cloud.elastic.co/](https://cloud.elastic.co/)).

# The cloud.id setting overwrites the `output.elasticsearch.hosts` and

# `setup.kibana.host` options.

# You can find the `cloud.id` in the Elastic Cloud web UI.

#cloud.id:

# The cloud.auth setting overwrites the `output.elasticsearch.username` and

# `output.elasticsearch.password` settings. The format is `<user>:<pass>`.

#cloud.auth:

#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
#output.logstash:

# The Logstash hosts

#hosts: ["localhost:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

#================================ Processors =====================================

# Configure processors to enhance or manipulate events generated by the beat.

processors:

- add\_host\_metadata: ~
- add\_cloud\_metadata: ~
- community\_id:  
fields:  
source\_ip: my\_source\_ip  
source\_port: my\_source\_port  
destination\_ip: my\_dest\_ip  
destination\_port: my\_dest\_port  
transport: proto  
icmp\_type: my\_icmp\_type  
icmp\_code: my\_icmp\_code  
target: network.community\_id

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

logging.selectors: ["\*"]

#============================== Xpack Monitoring ===============================

# auditbeat can export internal metrics to a central Elasticsearch monitoring

# cluster. This requires xpack monitoring to be enabled in Elasticsearch. The

# reporting is disabled by default.

# Set to true to enable the monitoring reporter.

#monitoring.enabled: false

#================================= Migration ==================================

# This allows to enable 6.7 migration aliases

#migration.6\_to\_7.enabled: true

---

<div class="post-metadata">

### Author: ![james007](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@james007](https://discuss.elastic.co/u/james007)
#### Post date: [May 31, 2019, 12:48pm UTC](https://discuss.elastic.co/t/community-id/183636/4 "2019-05-31T12:48:05Z")

</div>

I see that the processor is created in stdout.  
2019-05-31T08:35:04.359-0400 DEBUG [processors] processors/processor.go:93 Generated new processors: add\_host\_metadata=[netinfo.enabled=[false], cache.ttl=[5m0s]], add\_cloud\_metadata=null, community\_id=[target=network.community\_id, fields=[source\_ip=my\_source\_ip, source\_port=my\_source\_port, destination\_ip=my\_dest\_ip, destination\_port=my\_dest\_port, transport\_protocol=proto, icmp\_type=my\_icmp\_type, icmp\_code=my\_icmp\_code], seed=0]

I assume that any network connection would generate a community\_id. I tried pinging a site, establishing an SSH connection.

Thanks,

James

---

<div class="post-metadata">

### Author: ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)
#### Post date: [May 31, 2019, 12:50pm UTC](https://discuss.elastic.co/t/community-id/183636/5 "2019-05-31T12:50:42Z")

</div>

Format your snippets using the `</>` button otherwise the yaml is difficult to read.

The provided configuration is just an example.

```auto
      fields:
        source_ip: my_source_ip
        source_port: my_source_port
        destination_ip: my_dest_ip
        destination_port: my_dest_port
        transport: proto
        icmp_type: my_icmp_type
        icmp_code: my_icmp_code

```

This requires your event to contain fields called `my_source_ip`, `my_source_port`, etc, which Auditbeat is not setting.

I don't think any module in Auditbeat outputs source/destination IPs and protocol, which is the minimum needed for the community ID to be generated.

You should try with Packetbeat, which already generates the community\_id.

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [May 31, 2019, 1:25pm UTC](https://discuss.elastic.co/t/community-id/183636/6 "2019-05-31T13:25:38Z")

</div>

BTW The system/socket dataset will natively add the `network.community_id` in an upcoming release of Auditbeat. [https://github.com/elastic/beats/pull/12231](https://github.com/elastic/beats/pull/12231)

---

<div class="post-metadata">

### Author: ![james007](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@james007](https://discuss.elastic.co/u/james007)
#### Post date: [May 31, 2019, 9:42pm UTC](https://discuss.elastic.co/t/community-id/183636/7 "2019-05-31T21:42:15Z")

</div>

Thank you for the assistance. This has been great.

I built it from master yesterday and I see the changes in the src directory from the pull request, but I don't see a community\_id from the beat. I don't see any system or socket in the STDOUT when I ping or ssh to an external device.

Is there a configuration option I'm missing?

---

<div class="post-metadata">

### Author: ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)
#### Post date: [June 3, 2019, 6:43pm UTC](https://discuss.elastic.co/t/community-id/183636/8 "2019-06-03T18:43:34Z")

</div>

Hi @james007 - I think it might be easier to download a snapshot of Auditbeat 7.2 or master from [https://console.cloud.google.com/storage/browser/beats-ci-artifacts/snapshots/auditbeat/](https://console.cloud.google.com/storage/browser/beats-ci-artifacts/snapshots/auditbeat/). Can you check if that works?

Alternatively, can you share more details of how you built Auditbeat (esp. which command you used in which directory), the configuration you're using, and the log output?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 1, 2019, 8:43pm UTC](https://discuss.elastic.co/t/community-id/183636/9 "2019-07-01T20:43:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
