# File and kernel metricsets does not work together

**URL:** <https://discuss.elastic.co/t/file-and-kernel-metricsets-does-not-work-together/108036>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [November 16, 2017, 10:38pm UTC](https://discuss.elastic.co/t/file-and-kernel-metricsets-does-not-work-together/108036 "2017-11-16T22:38:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [November 16, 2017, 10:38pm UTC](https://discuss.elastic.co/t/file-and-kernel-metricsets-does-not-work-together/108036/1 "2017-11-16T22:38:59Z")

</div>

Hello,

I am trying to setup auditbeat to monitor both logins to the systems and filechanges but if I enable the file metricset the kernel one stop sending data into elasticsearch.

I have the following configuration:

```
auditbeat.modules:

- module: audit
  metricsets: [kernel]
  kernel.audit_rules: |
    -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -k access
    -w /etc/group -p wa -k identity
    -w /etc/passwd -p wa -k identity
    -w /etc/gshadow -p wa -k identity
    -w /etc/shadow -p wa -k identity
 
  module: audit
  metricsets: [file]
  file.paths:
  - /bin
  - /usr/bin
  - /sbin
  - /usr/sbin
  - /etc
  file.max_file_size: 100 MiB
  file.hash_types: [sha1] 

```

I really hope this is a configuration issue while I am aware that it is not yet a stable version.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2017, 7:39am UTC](https://discuss.elastic.co/t/file-and-kernel-metricsets-does-not-work-together/108036/2 "2017-11-17T07:39:58Z")

</div>

I think you are missing `-` in front of the second module declaration, as shown [in this example](https://www.elastic.co/guide/en/beats/auditbeat/current/configuration-auditbeat.html).

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [November 17, 2017, 2:33pm UTC](https://discuss.elastic.co/t/file-and-kernel-metricsets-does-not-work-together/108036/3 "2017-11-17T14:33:12Z")

</div>

Right, tanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:04am UTC](https://discuss.elastic.co/t/file-and-kernel-metricsets-does-not-work-together/108036/4 "2022-11-04T05:04:11Z")

</div>


