# How to write auditlogs output to local and logstash

**URL:** <https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [January 11, 2019, 2:20am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829 "2019-01-11T02:20:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![post2tr](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@post2tr](https://discuss.elastic.co/u/post2tr)\
**Post date:** [January 11, 2019, 2:20am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/1 "2019-01-11T02:20:05Z")

</div>

Using the auditbeat how to write the audit logs to the local disk ( for internal company requirements ) and logstash . Currently i get error message one outputs is allowed ie., either local or logstash .. The Dashboards,message parsing flexibility is not in Kibana available while using the filebeat for auditlogs.

Can anyone help !!

Thanks [//T.R](https://T.R)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 18, 2019, 10:22pm UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/2 "2019-01-18T22:22:06Z")

</div>

All of the Beats support configuring a single output.

If you are are on a kernel that supports multicast then one option that might meet your requirement would be to use auditd to simply write the audit logs to disk. Then run Auditbeat along side to receive the multicast broadcast of the messages and forward them to ES. Read the `socket_type` docs [here](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-auditd.html#_configuration_options_13) for details.

---

<div class="post-metadata">

**Author:** ![post2tr](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@post2tr](https://discuss.elastic.co/u/post2tr)\
**Post date:** [January 19, 2019, 3:53am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/3 "2019-01-19T03:53:35Z")

</div>

Thanks Andrew Kroh , for your response. Kernel ver : 3.10 CentOS 6.9 and explicitly defined the socket\_type: multicast .yml file and still while starting the auditbeat its returning below error.

To use this multicast option need to get subscription/license ?

===================  
2019-01-19T11:48:10.239+0800 INFO instance/beat.go:278 Setup Beat: auditbeat; Version: 6.5.1  
2019-01-19T11:48:13.244+0800 INFO add\_cloud\_metadata/add\_cloud\_metadata.go:319 add\_cloud\_metadata: hosting provider type not detected.  
2019-01-19T11:48:13.245+0800 INFO [publisher] pipeline/module.go:110 Beat name: [e9.test.com](http://e9.test.com)  
2019-01-19T11:48:13.245+0800 INFO [auditd] auditd/audit\_linux.go:104 auditd module is running as euid=0 on kernel=3.10.0-957.el7.x86\_64  
2019-01-19T11:48:13.245+0800 ERROR [auditd] auditd/audit\_linux.go:810 socket\_type is set to multicast but based on the kernel version, multicast audit subscriptions are not supported. Remove the socket\_type option to have auditbeat select the most suitable subscription method.  
2019-01-19T11:48:13.246+0800 INFO instance/beat.go:357 auditbeat stopped.  
2019-01-19T11:48:13.246+0800 ERROR instance/beat.go:800 Exiting: 1 error: 1 error: failed to create audit client: multicast socket\_type not available  
Exiting: 1 error: 1 error: failed to create audit client: multicast socket\_type not available

============================

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 19, 2019, 4:06am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/4 "2019-01-19T04:06:10Z")

</div>

The docs state:

> `multicast` can be used in kernel versions 3.16 and newer.

So unfortunately you won't be able to use the multicast option to receive traffic on CentOS 6.9.

---

<div class="post-metadata">

**Author:** ![post2tr](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@post2tr](https://discuss.elastic.co/u/post2tr)\
**Post date:** [January 19, 2019, 4:07am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/5 "2019-01-19T04:07:10Z")

</div>

From github , i see the source code trying to validate 3 conditions and i believe 2 conditions is met and one condition i am not sure how to check it .. The first condition ..

> <https://github.com/elastic/beats/blob/master/auditbeat/module/auditd/audit_linux.go>

isLocked := status.Enabled == auditLocked  
hasMulticast := hasMulticastSupport()  
hasRules := len(rules) \> 0

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 19, 2019, 5:27am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/6 "2019-01-19T05:27:09Z")

</div>

To check that you can use the `auditbeat show auditd-status` command to make Auditbeat list the kernel status info that contains the enabled state (0=disabled, 1=enabled, 2=locked).

---

<div class="post-metadata">

**Author:** ![post2tr](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@post2tr](https://discuss.elastic.co/u/post2tr)\
**Post date:** [January 19, 2019, 5:39am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/7 "2019-01-19T05:39:21Z")

</div>

> [@andrewkroh](#):
>
> auditbeat show auditd-status

Yes, i checked and noticed its not locked . Not sure why still having the above errors..  
All the 3 conditions ruled out.. ☹

[root@edge09 auditbeat-6.5.1-linux-x86\_64]# ./auditbeat show auditd-status  
enabled 1  
failure 1  
pid 14248  
rate\_limit 5000  
backlog\_limit 8192  
lost 121139  
backlog 0  
backlog\_wait\_time 0  
features 0x3d

---

<div class="post-metadata">

**Author:** ![post2tr](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@post2tr](https://discuss.elastic.co/u/post2tr)\
**Post date:** [January 19, 2019, 6:44am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/8 "2019-01-19T06:44:47Z")

</div>

Just notice your other github ticket ( #8382) on this same issue and tried the suggestions as well ..  
But not working for my case .. To meet internal compliance i need to store the audit logs in local servers as well ..

"[https://github.com/elastic/beats/issues/8382](https://github.com/elastic/beats/issues/8382)"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2019, 6:44am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829/9 "2019-02-09T06:44:48Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
