# In Ubuntu 18.04 auditbeat logs goes to syslog than /var/log/auditbeat

**URL:** <https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269>\
**Category:** SIEM\
**Created:** [November 3, 2019, 5:26am UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269 "2019-11-03T05:26:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joseph\_John](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_john/32/53907_2.png) [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Post date:** [November 3, 2019, 5:26am UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269/1 "2019-11-03T05:26:45Z")

</div>

Hi All,  
Good morning  
I am using Ubuntu 18.04 I have auditbeat installed and running on my system, in the auditbeat.yml files I have given the following

> logging.level: info  
> path.logs: /var/log/auditbeat

When I check for the logs, the logs file are not created in "/var/log/auditbeat" instead I see them on  
**/var/log/syslog**. Doubting permission issues I have given chmod 777 to /var/log/auditbeat [not a good idea, but for troubleshooting]

Guidance requested to send the logs to /var/log/auditbeat than to syslog  
thanks  
Joseph John

**Kibana version** :  
7.4.1   
**Elasticsearch version** :  
7.4.1  
**APM Server version** :  
7.4.1  
\*\*filebeat version \*\*  
7.4.1  
**APM Agent language and version** :  
NA  
**Logstash version**  
7.4.1-1

---

<div class="post-metadata">

**Author:** ![Joseph\_John](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_john/32/53907_2.png) [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Post date:** [November 3, 2019, 7:57am UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269/2 "2019-11-03T07:57:52Z")

</div>

Like to update and give this feedback  
while giving  
**auditbeat -c /etc/auditbeat/auditbeat.yml**  
the logs goes to the specified log dir  
I also did my package update, now my package details are

> **Elasticsearch** 7.4.2, **Kibana** 7.4.2 , **Auditbeat** 7.4.2 , **FileBeat** 7.4.2, **LogStash** 7.4.2-1 , **Metricbeat** 7.4.2

Any one facing the same issues with Ubuntu 18.04  
Thanks  
Joseph John

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [November 13, 2019, 10:39am UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269/3 "2019-11-13T10:39:46Z")

</div>

Hi Joseph,

To make sure I understand, `auditbeat -c /etc/auditbeat/auditbeat.yml` works as expected but when you start it via systemctl or similar it logs to syslog?

Can you try also setting `logging.to_files: true`?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 13, 2019, 9:03pm UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269/4 "2019-11-13T21:03:29Z")

</div>

With systemd the logs automatically output to stderr so that they are picked up in journald (all beats behave this way with their default systemd unit file). See [https://www.elastic.co/guide/en/beats/auditbeat/7.4/running-with-systemd.html](https://www.elastic.co/guide/en/beats/auditbeat/7.4/running-with-systemd.html) for details, include how to change the behavior.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2019, 9:03pm UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269/5 "2019-12-11T21:03:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
