# Filebeat Processing /var/log/secure

**URL:** <https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [July 10, 2019, 12:12pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758 "2019-07-10T12:12:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviator](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aviator](https://discuss.elastic.co/u/aviator)\
**Post date:** [July 10, 2019, 12:12pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/1 "2019-07-10T12:12:33Z")

</div>

Hi

ES 7.0.2  
Am trying to view the `Filebeat System New user and groups` dashboard but the results are sporadic at best.  
Filebeat 7.2.0 installed locally on ES instance and on remote machine to confirm. Configured to harvest /var/log/secure  
Add a user and watch in Discovery and the event(s) get shipped quickly (filebeat -e -d "\*") but the event may or may not turn up either in the dashboard or Discovery. Maybe an hour later but sometimes nothing.  
Clean install with no load on the machine (this is the only input configured to check performance)  
Ouput of

> GET filebeat-\*/\_search?q=_exists_:system.auth.useradd

shows the document arrives within a few seconds but again the Discovery does not reflect this.

Is there a default post process slowing things down before it becomes available? The syslog message log seems to be available without any delay just the auth.

Regards

Ed

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 10, 2019, 12:20pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/2 "2019-07-10T12:20:33Z")

</div>

Check the @timestamp of the event vs that of the log, it could be a timezone interpretation problem.

---

<div class="post-metadata">

**Author:** ![aviator](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aviator](https://discuss.elastic.co/u/aviator)\
**Post date:** [July 10, 2019, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/3 "2019-07-10T13:59:55Z")

</div>

Timestamps look to be in sync, perhaps spoke too soon on the ingest being ok, running the filebeat debug I see the two documents being created for an adduser command. They are being sent to

> filebeat-7.2.0-system-auth-pipeline

A check of the stats using

> GET \_nodes/stats/ingest

Shows the following under the auth pipeline (two below are the only failed entries)

> "geoip" : {  
> "count" : 491,  
> "time\_in\_millis" : 287,  
> "current" : 0,  
> "failed" : 366  
> }  
> },  
> {  
> "script" : {  
> "count" : 491,  
> "time\_in\_millis" : 27,  
> "current" : 0,  
> "failed" : 366

The previous count was 489 and failed 364 so the two documents being ingested are not getting processed correctly?

Where could I look for further troubleshooting?

Regards

Ed

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 10, 2019, 3:17pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/4 "2019-07-10T15:17:25Z")

</div>

Group fails are common, usually private ips. That won't fail ingest, just won't populate fields.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 10, 2019, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/5 "2019-07-10T15:18:07Z")

</div>

Geoip, spellfix....

---

<div class="post-metadata">

**Author:** ![aviator](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aviator](https://discuss.elastic.co/u/aviator)\
**Post date:** [July 10, 2019, 3:33pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/6 "2019-07-10T15:33:58Z")

</div>

This is a new install - previously used the elastic geoip module so went ahead and followed this:

> [Enrich events with geoIP information | Filebeat Reference [7.2] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.2/filebeat-geoip.html)

have stared at this issue for hours and probably cannot see the obvious - is the geoip enrichment for the auth pipeline named something other than geoip?

Regards

Ed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2019, 3:34pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758/7 "2019-08-07T15:34:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
