# KIBANA : xpack.security.audit issue

**URL:** <https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [February 24, 2021, 1:37pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347 "2021-02-24T13:37:21Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 24, 2021, 1:37pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/1 "2021-02-24T13:37:21Z")

</div>

hello,  
I'm trying to make audit for kibana like this doc :  
[https://www.elastic.co/guide/en/kibana/7.11/security-settings-kb.html#audit-logging-settings](https://www.elastic.co/guide/en/kibana/7.11/security-settings-kb.html#audit-logging-settings)

Here's my kib.yml :

# --------------------------------- Audit --------------------------------------

> xpack.security.audit.enabled: true  
> xpack.security.audit.appender:  
> kind: rolling-file  
> path: /var/log/kibana/audit.log  
> xpack.security.audit.appender.layout.kind: json  
> xpack.security.audit.appender.policy.kind: time-interval  
> xpack.security.audit.appender.policy.interval: 24h  
> xpack.security.audit.appender.strategy.kind: numeric  
> xpack.security.audit.appender.strategy.max: 365

and here's error log :

> Feb 24 14:23:35 srv-syslog kibana: FATAL Error: [config validation of [path]]: could not parse object value from json input  
> Feb 24 14:23:35 srv-syslog systemd: kibana.service: main process exited, code=exited, status=1/FAILURE  
> Feb 24 14:23:35 srv-syslog systemd: Unit kibana.service entered failed state.  
> Feb 24 14:23:35 srv-syslog systemd: kibana.service failed.  
> Feb 24 14:23:39 srv-syslog systemd: kibana.service holdoff time over, scheduling restart.

I'm sure i'm missing something or maybe syntax error in kib.yml but i don't know what.  
Thanks for help.  
Regards.  
Alex.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 24, 2021, 3:44pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/2 "2021-02-24T15:44:17Z")

</div>

Hey @Alex_Lum,

The pasted snippet is missing indentation. Can you verify that your actual `kibana.yml` has the `kind` and `path` properties indented like so:

```auto
xpack.security.audit.enabled: true
xpack.security.audit.appender:
   kind: rolling-file
   path: /var/log/kibana/audit.log
xpack.security.audit.appender.layout.kind: json
xpack.security.audit.appender.policy.kind: time-interval
xpack.security.audit.appender.policy.interval: 24h
xpack.security.audit.appender.strategy.kind: numeric
xpack.security.audit.appender.strategy.max: 365

```

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 24, 2021, 3:53pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/3 "2021-02-24T15:53:35Z")

</div>

> [@Larry\_Gregory](#):
>
> The pasted snippet is missing indentation. Can you verify that your actual `kibana.yml` has the `kind` and `path` properties indented like so:

yes, kind an path are intended with tabulations.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 24, 2021, 4:06pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/4 "2021-02-24T16:06:06Z")

</div>

Interesting. I get the same error message when I remove the indentations, but the config snippet that I pasted to you above works just fine for me.

Are there any other parts of your `kibana.yml` file with missing indentations?

What happens if you change the config to not use the "nested" format:

```auto
xpack.security.audit.enabled: true
xpack.security.audit.appender.kind: rolling-file
xpack.security.audit.appender.path: /var/log/kibana/audit.log
xpack.security.audit.appender.layout.kind: json
xpack.security.audit.appender.policy.kind: time-interval
xpack.security.audit.appender.policy.interval: 24h
xpack.security.audit.appender.strategy.kind: numeric
xpack.security.audit.appender.strategy.max: 365

```

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 24, 2021, 4:24pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/5 "2021-02-24T16:24:26Z")

</div>

> [@Larry\_Gregory](#):
>
> ```auto
> xpack.security.audit.enabled: true
> xpack.security.audit.appender.kind: rolling-file
> xpack.security.audit.appender.path: /var/log/kibana/audit.log
> xpack.security.audit.appender.layout.kind: json
> xpack.security.audit.appender.policy.kind: time-interval
> xpack.security.audit.appender.policy.interval: 24h
> xpack.security.audit.appender.strategy.kind: numeric
> xpack.security.audit.appender.strategy.max: 365
> 
> ```

Not same error (i have already tested ;)), but it can't read some param.  
BTW, i m in ELK 7.11.

> Feb 24 17:23:57 srv-syslog kibana: FATAL Error: [config validation of [xpack.security].audit.appender]: definition for this key is missing  
> Feb 24 17:23:57 srv-syslog systemd: kibana.service: main process exited, code=exited, status=1/FAILURE  
> Feb 24 17:23:57 srv-syslog systemd: Unit kibana.service entered failed state.  
> Feb 24 17:23:57 srv-syslog systemd: kibana.service failed.  
> Feb 24 17:24:00 srv-syslog systemd: kibana.service holdoff time over, scheduling restart.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 24, 2021, 5:16pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/6 "2021-02-24T17:16:00Z")

</div>

Would you mind sharing your full `kibana.yml` file, so I can try to reproduce this on my machine? I'll DM you a link with instructions to upload it, so we don't lose anything in translation between these discussion boards.

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 25, 2021, 7:48am UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/7 "2021-02-25T07:48:37Z")

</div>

HEllo Larry,  
I've upload kibana.yml using your link. Thanks for help.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 25, 2021, 12:32pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/8 "2021-02-25T12:32:38Z")

</div>

Thanks @Alex_Lum , that was helpful.

> yes, kind an path are intended with tabulations.

I should have noticed this earlier. Can you replace the tabulations with spaces? Using the file you sent, replacing the single tab with two spaces worked for me

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 25, 2021, 12:52pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/9 "2021-02-25T12:52:10Z")

</div>

Hello Larry,  
Same as not use nested format :

> Feb 25 13:50:28 srv-syslog kibana: FATAL Error: [config validation of [xpack.security].audit.appender]: definition for this key is missing  
> Feb 25 13:50:28 srv-syslog systemd: kibana.service: main process exited, code=exited, status=1/FAILURE  
> Feb 25 13:50:28 srv-syslog systemd: Unit kibana.service entered failed state.

Tested with one space and with two spaces.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 25, 2021, 12:55pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/10 "2021-02-25T12:55:02Z")

</div>

Thanks, I'll keep digging and let you know what I find. Configuration shouldn't be this hard! I'm sorry you're having so much trouble getting this up and running

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 25, 2021, 1:02pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/11 "2021-02-25T13:02:06Z")

</div>

Ok Larry, i will wait 😉

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 25, 2021, 1:38pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/12 "2021-02-25T13:38:49Z")

</div>

Alright, two things:

1. `xpack.security.audit.appender.strategy.max` has a maximum value of `100`. This isn't causing your current problem, but it'll be the next problem that Kibana will complain about.

2. The only way I can reproduce this specific error (` FATAL Error: [config validation of [xpack.security].audit.appender]: definition for this key is missing`) is to declare this config in an older version of Kibana: for example, `7.10`. Sorry for the silly question, but are you _absolutely sure_ that you're running version `7.11.1`? Is it possible for you to reinstall Kibana into a fresh location?

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 25, 2021, 1:52pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/13 "2021-02-25T13:52:09Z")

</div>

> [@Larry\_Gregory](#):
>
> only way I can reproduce this specific error ( ` FATAL Error: [config validation of [xpack.security].audit.appender]: definition for this key is missing` ) is to declare this config in an older version of Kibana: for example, `7.10` . Sorry for the silly question, but are you _absolutely sure_ that you're running vers

My bad ☹ here's i see on stack managment

# Welcome to Stack Management 7.10.2

I installed kibana from sources because yum and rpm packages were corrupted (unable to extract).  
I just saw that on 17/02/2021 there are new versions.  
I m really sorry for this.  
I will try to reinstall kibana from yum and from source if it's does not work.

Thanks for max hint 😉  
I will try tomorrow or this afternoon and let you know if it's work or not.

Thank you Larry.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [February 25, 2021, 2:45pm UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/14 "2021-02-25T14:45:31Z")

</div>

No worries, I'm glad we [probably] found the root cause! Let me know how you make out with the upgrade

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [February 26, 2021, 7:45am UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/15 "2021-02-26T07:45:14Z")

</div>

Hello Larry,  
i m trying to install latest kibana version (7.11.1) but yum package can't be unpacked and same for sources, some files cannot be untared. I will create a new topic for that and edit this one when i can test.  
Regards.

---

<div class="post-metadata">

**Author:** ![Alex\_Lum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_lum/32/84472_2.png) [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Post date:** [March 3, 2021, 10:41am UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/16 "2021-03-03T10:41:59Z")

</div>

everything is working good now.  
Thank you larry.  
Case can be closed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2021, 10:42am UTC](https://discuss.elastic.co/t/kibana-xpack-security-audit-issue/265347/17 "2021-03-31T10:42:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
