# Filebeat: permission denied

**URL:** <https://discuss.elastic.co/t/filebeat-permission-denied/330592>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [April 23, 2023, 9:05pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592 "2023-04-23T21:05:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![y34rz3r0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/y34rz3r0/32/124582_2.png) [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Post date:** [April 23, 2023, 9:05pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/1 "2023-04-23T21:05:46Z")

</div>

Hi all! Need your help in solving the problem:

```auto
Unexpected file opening error: 
"Failed opening /mnt/var/log/auth.log: open /mnt/var/log/auth.log: permission denied"

```

My environment:

- docker-compose
- filebeat:8.7.0
- user and group of auth.log is syslog:adm

What have I already tried:

- command: ["--strict.perms=false"]
- "$ chown root:root filebeat.yml" + "$ chmod 755 filebeat.yml"
- change image to filebeat:8.6.0

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 23, 2023, 10:01pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/2 "2023-04-23T22:01:37Z")

</div>

> [@y34rz3r0](#):
>
> `/mnt/var/log/auth.log`

What is the permission on

`ls -la /mnt/var/log`

Specifically, we want to know the permissions and mode on the `auth.log` file and the containing directory `/mnt/var/log`

> [@y34rz3r0](#):
>
> $ chown root:root filebeat.yml" + "$ chmod 755 filebeat.yml

This probably not going to help.

Filebeat is complaining that it can't read the log file not about its own configuration.

Filebeat is going to need to be able to read the file and if it's not in the same user and group then it's going to need to be 644 mode at the least.

Perhaps share your compose file... It's most likely the log mount does not have the correct permissions.

---

<div class="post-metadata">

**Author:** ![y34rz3r0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/y34rz3r0/32/124582_2.png) [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Post date:** [April 24, 2023, 10:25pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/3 "2023-04-24T22:25:03Z")

</div>

Thanks for your reply! Unfortunately, at the moment I can't see the permissions on /mnt/var/log/auth.log. I'll add this information a little later. As for my configuration, you can see everything here [GitHub - y34r-z3r0/elastic: Learning and testing elk-stack features](https://github.com/y34r-z3r0/elastic/)

---

<div class="post-metadata">

**Author:** ![y34rz3r0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/y34rz3r0/32/124582_2.png) [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Post date:** [April 25, 2023, 10:54am UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/4 "2023-04-25T10:54:43Z")

</div>

```auto
filebeat@filebeat:~$ ls -l /mnt/var/log/auth.log 
-rw-r----- 1 107 adm 55445 Apr 25 10:50 /mnt/var/log/auth.log

```

What is the best way to change the permissions for a file in a container?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 25, 2023, 12:29pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/5 "2023-04-25T12:29:44Z")

</div>

Hi @y34rz3r0

This is more of a docker mount issue than filebeat issue.

Perhaps you should read a bit about permissions and volumes

If you think about it docker compose or filebeat can only read or access files that the user that's running it can.

Otherwise, it'd be a huge security hole to just be able to run a docker or filebeat and read any file that a user didn't have permission to read.

Here's an article that might help

> **[Docker Files and Volumes: Permission Denied](https://mydeveloperplanet.com/2022/10/19/docker-files-and-volumes-permission-denied/)**
>
> Encountered a ‘Permission Denied’ error on a file copied to a Docker image or when accessing a file on a mounted volume within a Docker container? In this blog, you will learn why you g…

---

<div class="post-metadata">

**Author:** ![y34rz3r0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/y34rz3r0/32/124582_2.png) [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Post date:** [April 25, 2023, 4:23pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/6 "2023-04-25T16:23:47Z")

</div>

Thank you! I'll take a look at the docs and post the solution as soon as I figure it out.

---

<div class="post-metadata">

**Author:** ![y34rz3r0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/y34rz3r0/32/124582_2.png) [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Post date:** [May 2, 2023, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/7 "2023-05-02T16:33:15Z")

</div>

So, in this case, I decided to go the simplest way:

`sudo chmod o+r /var/log/auth.log`  
(in the system, not in the container)

And it works 🥂

I don’t know how correct this option is in terms of interfering with the security of the system, but the main thing for me now is that I can proceed to the next steps in learning ELK.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2023, 6:33pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592/8 "2023-05-30T18:33:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
