# Filebeat forward to Kibana ssh auth fail

**URL:** <https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 9, 2018, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709 "2018-10-09T20:50:33Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcoa](https://avatars.discourse-cdn.com/v4/letter/m/3e96dc/32.png) [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Post date:** [October 9, 2018, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/1 "2018-10-09T20:50:33Z")

</div>

Hello,  
I've filebeat and system module for check `ssh auth` but in Kibana dont register the ssh action.

My `filebeat.yml`:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/secure
    - /var/log/messages
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
setup.dashboards.enabled: true
setup.kibana:
  host: "192.168.x.x:5601"
output.elasticsearch:
  hosts: ["192.168.x.x:9200"]

```

and the `system module`:

```auto
- module: system
  syslog:
    enabled: true
    var.paths: ["/var/log/messages"]
  auth:
    enabled: true
    var.paths: ["/var/log/secure"]

```

My Index `Filebeat-*` is fine:

 ![51](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d370ad6bbf0eebb6b42674ebf4cecf7a53d4a51c.png)

But "Discover" i dont show `*ssh*` fields .

 ![04](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0ddef3b02d4e61d4835cc8d1c81fd28a3b75e08d.png)

¿what's wrong?

Thanks.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 12:22pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/2 "2018-10-10T12:22:25Z")

</div>

@Miguel, Are you getting SSH logs under filebeat index?  
If yes then make some activity regarding SSH on your remote machine and check then at kibana end or try to extend the time period for which you are watching the logs on Top Right hand in kibana.

Thanks.

---

<div class="post-metadata">

**Author:** ![mcoa](https://avatars.discourse-cdn.com/v4/letter/m/3e96dc/32.png) [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Post date:** [October 10, 2018, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/3 "2018-10-10T14:00:54Z")

</div>

Hello @Tek_Chand,  
Yes the filebeat "capture" the ssh login with debug mode:

```auto
"@timestamp": "2018-10-10T13:39:05.236Z",
"@metadata": {
  "beat": "filebeat",
  "type": "doc",
  "version": "6.4.1"
},
"offset": 36614,
"message": "Oct 10 10:38:56 test-1 sshd[12178]: Accepted password for mcoa from ::1 port 37236 ssh2",
"prospector": {
  "type": "log"
},
"input": {
  "type": "log"
},
"beat": {
  "version": "6.4.1",
  "name": "test-01.example.com",
  "hostname": "test-01.example.com"
},
"host": {
  "name": "test-01.example.com"
},
"source": "/var/log/secure"
}
2018-10-10T10:39:05.237-0300	DEBUG	[publish]	pipeline/processor.go:308	Publish event: {
"@timestamp": "2018-10-10T13:39:05.237Z",
"@metadata": {
  "beat": "filebeat",
  "type": "doc",
  "version": "6.4.1"
},
"beat": {
  "version": "6.4.1",
  "name": "test-01.example.com",
  "hostname": "test-01.example.com"
},
"host": {
  "name": "test-01.example.com"
},
"message": "Oct 10 10:38:56 test-1 sshd[12178]: pam_unix(sshd:session): session opened for user mcoa by (uid=0)",
"source": "/var/log/secure",
"offset": 36702,
"prospector": {
  "type": "log"
},
"input": {
  "type": "log"
}
}
2018-10-10T10:38:41.232-0300	DEBUG	[input]	log/input.go:195	input states cleaned up. Before: 1, After: 1, Pending: 0
2018-10-10T10:38:41.232-0300	INFO	pipeline/output.go:95	Connecting to backoff(elasticsearch(http://192.168.x.x:9200))
2018-10-10T10:38:41.232-0300	DEBUG	[elasticsearch]	elasticsearch/client.go:688	ES Ping(url=http://192.168.x.x:9200)
2018-10-10T10:38:41.235-0300	DEBUG	[harvester]	log/log.go:102	End of file reached: /var/log/secure; Backoff now.
2018-10-10T10:38:41.235-0300	DEBUG	[elasticsearch]	elasticsearch/client.go:711	Ping status code: 200
2018-10-10T10:38:41.235-0300	INFO	elasticsearch/client.go:712	Connected to Elasticsearch version 6.4.2
2018-10-10T10:38:41.235-0300	DEBUG	[elasticsearch]	elasticsearch/client.go:730	HEAD http://192.168.x.x:9200/_template/filebeat-6.4.1 <nil>
2018-10-10T10:38:41.237-0300	INFO	template/load.go:129	Template already exists and will not be overwritten.
2018-10-10T10:38:41.237-0300	INFO	pipeline/output.go:105	Connection to backoff(elasticsearch(http://192.168.x.x:9200)) established
2018-10-10T10:38:41.241-0300	DEBUG	[elasticsearch]	elasticsearch/client.go:321	PublishEvents: 15 events have been published to elasticsearch in 4.368835ms.

```

This registre is shown from Kibana, but not "parser" with system module:

 ![log](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d1a46fb85618b4d1a2f58f19789508238987599.png)

The strange is the next error:

```auto
2018-10-10T10:38:40.257-0300	DEBUG	[processors]	processors/processor.go:66	Processors:
2018-10-10T10:38:40.257-0300	DEBUG	[input]	log/config.go:200	recursive glob enabled
2018-10-10T10:38:40.257-0300	DEBUG	[input]	log/input.go:147	exclude_files: [(?-s:.)gz(?-m:$)]. Number of stats: 6
2018-10-10T10:38:40.257-0300	ERROR	fileset/factory.go:105	Error creating input: Can only start an input when all related states are finished: {Id:16871871-64768 Finished:false Fileinfo:0xc42044d6c0 Source:/var/log/secure Offset:34972 Timestamp:2018-10-10 10:38:40.239207208 -0300 -03 m=+28.383377111 TTL:-1ns Type:log Meta:map[] FileStateOS:16871871-64768}
2018-10-10T10:38:40.257-0300	ERROR	[reload]	cfgfile/list.go:104	Error creating runner from config: Can only start an input when all related states are finished: {Id:16871871-64768 Finished:false Fileinfo:0xc42044d6c0 Source:/var/log/secure Offset:34972 Timestamp:2018-10-10 10:38:40.239207208 -0300 -03 m=+28.383377111 TTL:-1ns Type:log Meta:map[] FileStateOS:16871871-64768

```

any suggestions ?

Thanks.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 11, 2018, 4:36am UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/4 "2018-10-11T04:36:44Z")

</div>

@Mcoa, I have checked again your `filebeat.yml` file config in first post. You have enabled the input prospectors and filebeat config module is set to false. So logs are not going through system module.

So make the below changes in your `filebeat.yml` config file:

```auto
filebeat.inputs:
- type: log
  enabled: false
  paths:
# - /var/log/secure
# - /var/log/messages
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
setup.dashboards.enabled: true
setup.kibana:
  host: "192.168.x.x:5601"
output.elasticsearch:
  hosts: ["192.168.x.x:9200"]

```

Please let me know if you still face any problem.

Thanks.

---

<div class="post-metadata">

**Author:** ![mcoa](https://avatars.discourse-cdn.com/v4/letter/m/3e96dc/32.png) [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Post date:** [October 11, 2018, 1:38pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/5 "2018-10-11T13:38:59Z")

</div>

Hello @Tek_Chand, I changed my config file:

```auto
filebeat.inputs:
- type: log
  enabled: false
  paths:
# - /var/log/secure
# - /var/log/message
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
setup.dashboards.enabled: true
setup.kibana:
  host: "192.168.x.x:5601"
output.elasticsearch:
  hosts: ["192.168.x.x:9200"]

```

And my system module

```auto
[root@test-1 filebeat]# cat modules.d/system.yml
- module: system
  auth:
    enabled: true
    var.paths: ["/var/log/secure"]

```

But, i've the same behavior. Is strange, because can see the json by Kibana, but isn't with system module flag.

 ![20](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0efc06ddc962fb47ead831d749b8630e256a3f46.png)

Regards.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 12, 2018, 3:14am UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/6 "2018-10-12T03:14:34Z")

</div>

@Mcoa, Now its really strange. Can you please give me the output of below command:

```auto
$filebeat modules list

```

One more question for you..how you enable the filebeat system module?  
I am hope so you have used the below command to enable the filebeat module

```auto
$filebeat modules enable system

```

Thanks.

---

<div class="post-metadata">

**Author:** ![mcoa](https://avatars.discourse-cdn.com/v4/letter/m/3e96dc/32.png) [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Post date:** [October 12, 2018, 3:45am UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/7 "2018-10-12T03:45:35Z")

</div>

Hello @Tek_Chand,  
The output command:

```auto
[root@web-1 ~]# filebeat modules list
Enabled:
system

Disabled:
apache2
auditd
elasticsearch
icinga
iis
kafka
kibana
logstash
mongodb
mysql
nginx
osquery
postgresql
redis
traefik

```

And yes, for enable system module i used that command.

thanks.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 12, 2018, 3:51am UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/8 "2018-10-12T03:51:33Z")

</div>

@mcoa, Thanks for your efforts.

According to your current configuration everything seems fine. Its really weird.

Have you restarted the filebeat service after making the changes in `filebeat.yml` file?

Thanks.

---

<div class="post-metadata">

**Author:** ![mcoa](https://avatars.discourse-cdn.com/v4/letter/m/3e96dc/32.png) [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Post date:** [October 12, 2018, 4:16am UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/9 "2018-10-12T04:16:39Z")

</div>

@Tek_Chand , Yes i restarted the filebeat service after any change.

Thanks.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 15, 2018, 10:46pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/10 "2018-10-15T22:46:01Z")

</div>

The system module does not parse old logs, as the file has been visited in the past. Newer logs should be parse though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2018, 10:46pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709/11 "2018-11-12T22:46:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
