# Issues installing Auditbeat on Oracle Linux and Red Hat

**URL:** <https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [September 9, 2018, 6:46am UTC](https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847 "2018-09-09T06:46:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![homood](https://avatars.discourse-cdn.com/v4/letter/h/e0b2c6/32.png) [@homood](https://discuss.elastic.co/u/homood)\
**Post date:** [September 9, 2018, 6:46am UTC](https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847/1 "2018-09-09T06:46:27Z")

</div>

I am trying to install Auditbeat on Oracle Linux 6.8 and Red Hat 7.5 but I can't run the service after installation.

The following are the error messages I get:

**On Oracle Linux:**  
2018-09-03T09:04:49.775+0300 INFO instance/beat.go:225 Setup Beat: auditbeat; Version: 6.3.2  
2018-09-03T09:04:49.775+0300 DEBUG [beat] instance/beat.go:242 Initializing output plugins  
2018-09-03T09:04:49.775+0300 DEBUG [processors] processors/processor.go:49 Processors:  
2018-09-03T09:04:49.775+0300 DEBUG [publish] pipeline/consumer.go:120 start pipeline event consumer  
2018-09-03T09:04:49.775+0300 INFO pipeline/module.go:81 Beat name: [server2.com](http://server2.com)  
2018-09-03T09:04:49.775+0300 DEBUG [modules] beater/metricbeat.go:81 Register [ModuleFactory:[], MetricSetFactory:[auditd/auditd, file\_integrity/file]]  
2018-09-03T09:04:49.776+0300 DEBUG [processors] processors/processor.go:49 Processors:  
2018-09-03T09:04:49.776+0300 INFO [auditd] auditd/audit\_linux.go:65 auditd module is running as euid=0 on kernel=2.6.39-400.284.1.el6uek.x86\_64  
2018-09-03T09:04:49.776+0300 ERROR [auditd] auditd/audit\_linux.go:655 Cannot continue: audit configuration is locked in the kernel (enabled=2) which prevents using unicast sockets. Multicast audit subscriptions are not available in this kernel. Disable locking the audit configuration to use auditbeat.  
2018-09-03T09:04:49.776+0300 ERROR instance/beat.go:691 Exiting: 1 error: 1 error: failed to create audit client: no connection to audit available  
Exiting: 1 error: 1 error: failed to create audit client: no connection to audit available

**On Red Hat:**  
-- Unit auditbeat.service has begun starting up.  
Sep 03 09:13:08 [server1.com](http://server1.com) auditbeat[60883]: Exiting: 1 error: 1 error: failed to create audit client: no connection to audit availa  
Sep 03 09:13:08 [server1.com](http://server1.com) systemd[1]: auditbeat.service: main process exited, code=exited, status=1/FAILURE  
Sep 03 09:13:08 [server1.com](http://server1.com) systemd[1]: Unit auditbeat.service entered failed state.  
Sep 03 09:13:08 [server1.com](http://server1.com) systemd[1]: auditbeat.service failed.  
Sep 03 09:13:08 [server1.com](http://server1.com) systemd[1]: auditbeat.service holdoff time over, scheduling restart.  
Sep 03 09:13:08 [server1.com](http://server1.com) systemd[1]: start request repeated too quickly for auditbeat.service  
Sep 03 09:13:08 [server1.com](http://server1.com) systemd[1]: Failed to start auditbeat.  
-- Subject: Unit auditbeat.service has failed

I hear that this is happening because auditing is enabled on kernel at boot time. However disabling it will require a reboot which is not allowed.

Is there anyway to resolve this without a reboot?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 10, 2018, 7:26pm UTC](https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847/2 "2018-09-10T19:26:27Z")

</div>

> [@homood](#):
>
> Cannot continue: audit configuration is locked in the kernel (enabled=2) which prevents using unicast sockets. Multicast audit subscriptions are not available in this kernel. Disable locking the audit configuration to use auditbeat.

The problem is that the kernel's audit configuration has been set to an immutable state. This usually is done as a security measure to prevent anything from disabling auditing or changing the rules. The only way to undo it is reboot. Prior to rebooting you'll want to modify your auditd configuration to remove the immutable flag (`-e 2` from your auditd config). See `-e` in [https://linux.die.net/man/8/auditctl](https://linux.die.net/man/8/auditctl).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2018, 7:26pm UTC](https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847/3 "2018-10-01T19:26:28Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
