# Filebeat module to see system logins

**URL:** https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519
**Category:** Beats
**Tags:** filebeat
**Created:** [November 16, 2020, 11:59am UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519 "2020-11-16T11:59:41Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![headtea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/headtea/32/24271_2.png) [@headtea](https://discuss.elastic.co/u/headtea)
#### Post date: [November 16, 2020, 11:59am UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519/1 "2020-11-16T11:59:41Z")

</div>

I have to keep track of system logins with filebeat. Filebeat has a default dashboard called `[Filebeat System] SSH login attempts ECS` which seems perfect. So to use that, I went to one of the machines, stopped filebeat, ran `filebeat modules enable system`, and then started filebeat again.

The only problem is that I can't see the data in the dashboard, [it's empty](https://i.imgur.com/OP3sIZM.png), even though other data from that machine is visible in kibana. The flow is `remote-machine > logstash > ES < kibana`. If it matters, [this is my logstash config](https://pastebin.com/VK1gEKTz).

Does anyone happen to know why it's not showing up?

Thanks ahead.

EDIT: Found this in logstash log:

```
[2020-11-16T15:28:40,864][WARN][logstash.outputs.elasticsearch][main][273fbeeaf4d005660ef3730f09d3f76b92894ab8b1d7f2e60e9468d752981a3a] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"filebeat-7.9.0-2020.11.16", :routing=>nil, :_type=>"_doc", :pipeline=>"filebeat-7.9.0-system-auth-pipeline"}, #<LogStash::Event:0x31949971>], :response=>{"index"=>{"_index"=>"filebeat-7.9.0-2020.11.16", "_type"=>"_doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"pipeline with id [filebeat-7.9.0-system-auth-pipeline] does not exist"}}}}
```

---

<div class="post-metadata">

### Author: ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)
#### Post date: [November 16, 2020, 12:12pm UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519/2 "2020-11-16T12:12:17Z")

</div>

Hi,  
What is your machine OS? because the system module is not supported on windows. accourding to [filebeat docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-system.html#_compatibility_34):

> This module is not available for Windows.

---

<div class="post-metadata">

### Author: ![headtea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/headtea/32/24271_2.png) [@headtea](https://discuss.elastic.co/u/headtea)
#### Post date: [November 16, 2020, 12:12pm UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519/3 "2020-11-16T12:12:58Z")

</div>

Thanks for the response,

It's CentOS 7

---

<div class="post-metadata">

### Author: ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)
#### Post date: [November 16, 2020, 12:18pm UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519/4 "2020-11-16T12:18:34Z")

</div>

> [@headtea](#):
>
> It's CentOS 7

So why don't you use auditbeat? I'm not sure but I think it supports system logins.  
There's also [auditd module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-auditd.html) for filebeat.

---

<div class="post-metadata">

### Author: ![headtea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/headtea/32/24271_2.png) [@headtea](https://discuss.elastic.co/u/headtea)
#### Post date: [November 16, 2020, 12:21pm UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519/5 "2020-11-16T12:21:16Z")

</div>

Thanks for the response.

I'm testing it now on a CentOS 7 machine, if I get that to work, I'll test on a CentOS 5 machine which can only run filebeat (auditbeat is not working on CentOS 5). I'm just not quite sure what to enable with auditd to see the same data.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 14, 2020, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519/7 "2020-12-14T15:14:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
