# Filebeat with sophos module

**URL:** <https://discuss.elastic.co/t/filebeat-with-sophos-module/290867>\
**Category:** Beats\
**Tags:** beats-module\
**Created:** [December 3, 2021, 10:40am UTC](https://discuss.elastic.co/t/filebeat-with-sophos-module/290867 "2021-12-03T10:40:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanil.ramachandran](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@sanil.ramachandran](https://discuss.elastic.co/u/sanil.ramachandran)\
**Post date:** [December 3, 2021, 10:40am UTC](https://discuss.elastic.co/t/filebeat-with-sophos-module/290867/1 "2021-12-03T10:40:00Z")

</div>

Hello,  
I am very new to elk.  
I have managed to install elasticsearch,kibana and filebeat in ubuntu server, managed to enable sophos module and manged to receive syslog messages from the appliance using rsyslog server. But I am not getting this data in to Elasticsearch.  
Can some one help me with this? below are my sophos module config and filebeat.yml.

## sophos.yml

- module: sophos  
xg:  
enabled: true  
var.input: file  
var.paths: ["/var/log/hostname/\*.log"]

* * *

## Filebeat.yml

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: log

# Change to true to enable this input configuration.

# enabled: true

# Paths that should be crawled and fetched. Glob based paths.

#paths:  
- /var/log/\*.log  
#- c:\programdata\elasticsearch\logs\*

# Exclude lines. A list of regular expressions to match. It drops the lines that are

# matching any regular expression from the list.

#exclude\_lines: ['^DBG']

# Include lines. A list of regular expressions to match. It exports the lines that are

# matching any regular expression from the list.

#include\_lines: ['^ERR', '^WARN']

# Exclude files. A list of regular expressions to match. Filebeat drops the files that

# are matching any regular expression from the list. By default, no files are dropped.

#exclude\_files: ['.gz$']

# Optional additional fields. These fields can be freely picked

# to add additional information to the crawled log files for filtering

#fields:

# level: debug

# review: 1

### Multiline options

# ============================== Filebeat modules ==============================

filebeat.config.modules:

# Glob pattern for configuration loading

path: ${path.config}/modules.d/\*.yml

# Set to true to enable config reloading

reload.enabled: false

# Period on which files under path should be checked for changes

#reload.period: 10s

# ======================= Elasticsearch template setting =======================

setup.template.settings:  
index.number\_of\_shards: 1  
#index.codec: best\_compression  
#\_source.enabled: false

# =================================== Kibana ===================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.

# This requires a Kibana endpoint configuration.

setup.kibana:

# Kibana Host

# Scheme and port can be left out and will be set to the default (http and 5601)

# In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)

# IPv6 addresses should always be defined as: https://[2001:db8::1]:5601

#host: "localhost:5601"

# Kibana Space ID

# ID of the Kibana Space into which the dashboards should be loaded. By default,

# the Default Space will be used.

#space.id:

# ---------------------------- Elasticsearch Output ----------------------------

output.elasticsearch:

# Array of hosts to connect to.

hosts: ["localhost:9200"]

# Protocol - either `http` (default) or `https`.

#protocol: "https"

# Authentication credentials - either API key or username/password.

#api\_key: "id:api\_key"  
#username: "elastic"  
#password: "changeme"

# ------------------------------ Logstash Output -------------------------------

#output.logstash:

# The Logstash hosts

#hosts: ["localhost:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2021, 12:40pm UTC](https://discuss.elastic.co/t/filebeat-with-sophos-module/290867/2 "2021-12-31T12:40:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
