# Filebeat/Logstash doesn't send system.auth.\*.\* field data to Elastic Search - v 7.14

**URL:** https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793
**Category:** Beats
**Tags:** beats-module, filebeat
**Created:** [August 18, 2021, 9:04am UTC](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793 "2021-08-18T09:04:21Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![angheladrianclaudiu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angheladrianclaudiu/32/93313_2.png) [@angheladrianclaudiu](https://discuss.elastic.co/u/angheladrianclaudiu)
#### Post date: [August 18, 2021, 9:04am UTC](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793/1 "2021-08-18T09:04:21Z")

</div>

I've installed ELK stack with steps described here:

[Current Elastic Release (7.14)](https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html)

[Current Kibana Release (7.14)](https://www.elastic.co/guide/en/kibana/current/deb.html)

[Current Logstash Release (7.14)](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html#package-repositories)

[Current Filebeat Release (7.14)](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html)

I also used the Logstash configuration presented here with the note under it: [Beats input plugin | Logstash Reference [7.14] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#_description_6)

However, after I've run the commands below I couldn't see any data in the loaded dashboards in Kibana:

```auto
sudo filebeat setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'

sudo filebeat setup -e -E output.logstash.enabled=false -E output.elasticsearch.hosts=['localhost:9200'] -E setup.kibana.host=localhost:5601

```

It should be something like this:

 ![filebeat-system](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95bfc3fecca78851bc104468427820b5c58ca7fb.jpeg)

But it looks like below:

 ![kibana-local](https://us1.discourse-cdn.com/elastic/original/3X/d/a/daf84bec8f348339901d192a3d56c11e3f114bf2.jpeg)

"No results found" is shown in all 4 dashboards: **Syslog | Sudo commands | SSH Logins | New users and groups**

Also, when I tried to lookup data in Discovery and search for system.auth.ssh.events for example I couldn't find anything:

 ![ssh-events](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f6af4cce6839be49abd79802f27200674f04ffa2.jpeg)

What is the problem?

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [August 18, 2021, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793/2 "2021-08-18T12:15:30Z")

</div>

Did u enable the filebeat system module?? You also need to configure the elasticsearch output when u run setup to load the index template, mappings, and ingest pipelines...

---

<div class="post-metadata">

### Author: ![angheladrianclaudiu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angheladrianclaudiu/32/93313_2.png) [@angheladrianclaudiu](https://discuss.elastic.co/u/angheladrianclaudiu)
#### Post date: [August 18, 2021, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793/3 "2021-08-18T15:01:12Z")

</div>

@legoguy1000 Sure. I've enabled the system module and configured logstash to read from filebeat input and send to elasticsearch. Please check below:

```auto
filebeat modules list

```

![filebeat-modules](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc5885f4e233061a46883399423920723aaaede6.jpeg)

```auto
cat /etc/filebeat/modules.d/system.yml

```

 ![filebeat-system-config](https://us1.discourse-cdn.com/elastic/original/3X/4/4/448249464d1f3df1176501c26193a536009b631f.jpeg)

```auto
cat /etc/logstash/cond.d/beats-input-output.conf

```

 ![beats-input-output-conf](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc061398dc427a40c633b7049e702c25abceed96.jpeg)

These were setup before running the commands in the original post.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 15, 2021, 5:01pm UTC](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793/4 "2021-09-15T17:01:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
