# Filebeat 6.2.4 running as root on Red Hat Linux

**URL:** <https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 16, 2018, 8:50am UTC](https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067 "2018-05-16T08:50:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![solo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solo/32/29084_2.png) [@solo](https://discuss.elastic.co/u/solo)\
**Post date:** [May 16, 2018, 8:50am UTC](https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067/1 "2018-05-16T08:50:48Z")

</div>

Hi.

Somehow Filebat insists on running as root, and not as filebeat user.  
Should not Filebeat run as the filebeat user?

My setup:  
Linux: Red Hat Enterprise Linux Server release 6.9  
Java: openjdk version "1.8.0\_161"  
Filebeat version: filebeat-6.2.4-x86\_64.rpm

How I installed Filebeat:  
sudo rpm -ivh filebeat-6.2.4-x86\_64.rpm

How I start Filebat:  
sudo service filebeat start

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [May 16, 2018, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067/2 "2018-05-16T13:55:47Z")

</div>

By default, we start Filebeat as the root user to be able to read all the logs generated by all application, but nothing prevents you from editing the startup scripts to make FB run as another user. You need to make sure the users/group have the right privileges to read and stat them.

related post with a few tricks: [Filebeat as a non-root user](https://discuss.elastic.co/t/filebeat-as-a-non-root-user/58946/12)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 16, 2018, 2:42pm UTC](https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067/3 "2018-05-16T14:42:46Z")

</div>

With RHEL 6 you will be using SysV to start Filebeat. The [init.d script](https://github.com/elastic/beats/blob/4c1aa5bd68f79cd1febd48809967d03acf43d0ff/dev-tools/packer/platforms/centos/init.j2#L25-L30) sources `/etc/sysconfig/filebeat` if it exists so that you can set `BEAT_USER` in order to override the default value of `root`.

```auto
# File: /etc/sysconfig/filebeat
BEAT_USER=my_custom_user

```

Then you must `chown -R` the config files under `/etc/filebeat` to ensure that Filebeat starts. Filebeat [checks ownership and permissions](https://www.elastic.co/guide/en/beats/libbeat/6.2/config-file-permissions.html).

I'd test filebeat as your custom user too.

```auto
sudo su - my_custom_user
filebeat test config -e

```

---

<div class="post-metadata">

**Author:** ![solo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solo/32/29084_2.png) [@solo](https://discuss.elastic.co/u/solo)\
**Post date:** [May 22, 2018, 7:13am UTC](https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067/4 "2018-05-22T07:13:29Z")

</div>

Thanks andrewkroh, I can test it today.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2018, 11:36am UTC](https://discuss.elastic.co/t/filebeat-6-2-4-running-as-root-on-red-hat-linux/132067/6 "2018-06-21T11:36:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
