Filebeat - apport.log: permission denied

Hi,
I'm trying to configure and run Filebeat for one of the training topics related to Lab 4.2: Extracting Events and am getting the below error:
2021-02-02T21:46:53.121Z ERROR log/input.go:519 Harvester could not be started on new file: /var/log/apport.log, Err: error setting up harvester: Harvester setup failed. Unexpected file opening error: Failed opening /var/log/apport.log: open /var/log/apport.log: permission denied

Please assist

I see a couple of issues:

  1. The lab does not ask you to extract events from a file named /var/log/apport.log
  2. If you do have that file on your system, the elastic user that is starting Filebeat does not have access to it, as stated in the error message

What step are you on in that lab?

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.