# Configure Packetbeat prior to building MacOS pkg

**URL:** <https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [November 20, 2020, 11:40pm UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204 "2020-11-20T23:40:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![AaronWF](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@AaronWF](https://discuss.elastic.co/u/AaronWF)\
**Post date:** [November 20, 2020, 11:41pm UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/1 "2020-11-20T23:41:00Z")

</div>

I am building beats on MacOS for the native integration feature, I have successfully built & deployed auditbeat, and during the build process I was able to find the file which the build was using in the template.

File looks like `auditbeat.yml.tmpl`

However, in the packetbeat directory, no such file exists.

To anyone who has built a beat from source, where do you find the packetbeat.yml source file that the build will use? Logs have shown that the source file is in the packetbeat.tar.gz file, but when I edit and rebuild, it goes back to the stock configuration.

Editing `packetbeat.yml` file in the base directory as well as `build/package/packebeat-darwin-amd64.tar.gz/packetbeat.yml` does nothing.

Anyone know where else I should look?

Screenshots of the directories attached below

Screenshot of auditbeat build directory:

 ![Screen Shot 2020-11-20 at 3.33.27 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/2/42b1c9c2209859bd12df775fa245c4ae76860c68.png)

Screenshot of packebeat build directory:

 ![Screen Shot 2020-11-20 at 3.33.58 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f1304f98e0e031c3d0b009fc0f57857cc90d48a.png)

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 23, 2020, 12:49am UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/2 "2020-11-23T00:49:01Z")

</div>

Is the file you're looking for one of these: [https://github.com/elastic/beats/tree/master/packetbeat/\_meta/config](https://github.com/elastic/beats/tree/master/packetbeat/_meta/config)?

Shaunak

---

<div class="post-metadata">

**Author:** ![AaronWF](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@AaronWF](https://discuss.elastic.co/u/AaronWF)\
**Post date:** [November 23, 2020, 10:11pm UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/3 "2020-11-23T22:11:06Z")

</div>

Hi Shaunak,

So I went ahead and edited one of those \_meta files and that got me halfway there. I was able to disable flows and other things, however, I can't find where the elastic cloud settings should be set.

I'm attempting to build a packebeat installer with everything pre-configured so I can deploy it to all devices with no setup from the user.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 24, 2020, 12:51am UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/4 "2020-11-24T00:51:18Z")

</div>

Hi Aaron,

As you probably know, Packetbeat is one of many Beats. All Beats have some common features, e.g. the Elasticsearch output. These common features are implemented in a shared library called `libbeat`. Similarly, any configuration associated with these common features is also defined under the `libbeat` folder. So I'm guessing the Elastic Cloud settings you're referring to are in here: [https://github.com/elastic/beats/blob/master/libbeat/\_meta/config.yml.tmpl](https://github.com/elastic/beats/blob/master/libbeat/_meta/config.yml.tmpl).

Hope that helps,

Shaunak

---

<div class="post-metadata">

**Author:** ![AaronWF](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@AaronWF](https://discuss.elastic.co/u/AaronWF)\
**Post date:** [November 24, 2020, 1:04am UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/5 "2020-11-24T01:04:22Z")

</div>

Hi Shaunak,

Thank you for your help! I'll put my elastic cloud settings in the file there.

Perhaps a feature request could be adding those .tmpl files in every beat build (like Auditbeat in my original post) so users can easily configure them?

Thank you again for you assistance 🙂

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 24, 2020, 2:57am UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/6 "2020-11-24T02:57:39Z")

</div>

Hi Aaron,

If you have a GitHub account, feel free to make this request (and reference this discuss post) via a GitHub issue in [https://github.com/elastic/beats](https://github.com/elastic/beats). That way you can follow along on progress, have input on any discussions, etc.

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2020, 4:57am UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204/7 "2020-12-22T04:57:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
