# Metricset 'audit/kernel' is not registered, module not found

**URL:** <https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [February 11, 2018, 12:55am UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353 "2018-02-11T00:55:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rdesanno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdesanno/32/13607_2.png) [@rdesanno](https://discuss.elastic.co/u/rdesanno)\
**Post date:** [February 11, 2018, 12:55am UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/1 "2018-02-11T00:55:36Z")

</div>

I'm stumped here. I'm using salt to deploy auditbeat across multiple CentOS7 hosts but found at least one server where auditbeat will not start and giving me the following error:

2018-02-10T19:30:18.733-0500 ERROR instance/beat.go:667 Exiting: 2 errors: 1 error: metricset 'audit/kernel' is not registered, module not found; 1 error: metricset 'audit/file' is not registered, module not found

Now this is the same config that am I using on multiple like hosts so i'm pretty sure that the config is correct and missing something obvious on this one host but cant for the life of me figure out what.

My modules config looks like this:

```auto
#========================== Modules configuration =============================
auditbeat.modules:
  - module: audit
    metricsets: [kernel]
    kernel.resolve_ids: true
    kernel.failure_mode: silent
    kernel.backlog_limit: 8196
    kernel.rate_limit: 0
    kernel.include_raw_message: false
    kernel.include_warnings: false
    kernel.audit_rules: |
      -a always,exit -F arch=b32 -S all -F key=32bit-abi

    file.scan_at_start: true
    file.max_file_size: 100 MiB

```

Anyone come across this error or can point me in a general direction on where to start looking?

---

<div class="post-metadata">

**Author:** ![rdesanno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdesanno/32/13607_2.png) [@rdesanno](https://discuss.elastic.co/u/rdesanno)\
**Post date:** [February 11, 2018, 1:17am UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/2 "2018-02-11T01:17:37Z")

</div>

Im wrong and it's definitely a config issue but still not sure why. Still doing some testing around this to see where i'm going wrong

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 12, 2018, 10:43am UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/3 "2018-02-12T10:43:13Z")

</div>

Are you using Auditbeat 6.2? If not, I strongly suggest you upgrade to it because starting with 6.2, Auditbeat is GA. Your config looks like it's for pre-6.2 Auditbeat (still refers to "metricsets"), the 6.2 config should be simpler.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 12, 2018, 6:41pm UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/4 "2018-02-12T18:41:15Z")

</div>

Here's some information about the changes in version 6.2: [https://www.elastic.co/guide/en/beats/auditbeat/6.2/auditbeat-breaking-changes.html](https://www.elastic.co/guide/en/beats/auditbeat/6.2/auditbeat-breaking-changes.html)

---

<div class="post-metadata">

**Author:** ![Guillaume\_Bettayeb](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@Guillaume\_Bettayeb](https://discuss.elastic.co/u/Guillaume_Bettayeb)\
**Post date:** [August 8, 2018, 10:24am UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/5 "2018-08-08T10:24:32Z")

</div>

I am having the exact same issue on Centos 7 with Auditbeat version 6.3:

[root@Auditd auditbeat]# tail /var/log/auditbeat/auditbeat  
2018-08-08T10:47:18.417+0100 INFO instance/beat.go:225 Setup Beat: auditbeat; Version: 6.3.2  
2018-08-08T10:47:18.417+0100 DEBUG [beat] instance/beat.go:242 Initializing output plugins  
2018-08-08T10:47:18.417+0100 DEBUG [processors] processors/processor.go:49 Processors:  
2018-08-08T10:47:18.417+0100 DEBUG [publish] pipeline/consumer.go:120 start pipeline event consumer  
2018-08-08T10:47:18.417+0100 INFO pipeline/module.go:81 Beat name: Auditd  
2018-08-08T10:47:18.417+0100 DEBUG [modules] beater/metricbeat.go:81 Register [ModuleFactory:[], MetricSetFactory:[auditd/auditd, file\_integrity/file]]  
2018-08-08T10:47:18.417+0100 DEBUG [processors] processors/processor.go:49 Processors:  
2018-08-08T10:47:18.418+0100 DEBUG [processors] processors/processor.go:49 Processors:  
2018-08-08T10:47:18.418+0100 INFO instance/beat.go:275 auditbeat stopped.  
2018-08-08T10:47:18.418+0100 ERROR instance/beat.go:691 Exiting: 2 errors: 1 error: metricset 'audit/kernel' is not registered, module not found; 1 error: metricset 'audit/file' is not registered, module not found

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 14, 2018, 2:58pm UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/6 "2018-08-14T14:58:05Z")

</div>

The exact same solution applies. You'll need to update your configuration used with any Auditbeat beta releases (pre v6.2) to work with versions \>=6.2.0.

See the examples in [https://www.elastic.co/guide/en/beats/auditbeat/6.2/auditbeat-breaking-changes.html](https://www.elastic.co/guide/en/beats/auditbeat/6.2/auditbeat-breaking-changes.html) or the configuration files that are included with the 6.3.2 package that you installed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:13am UTC](https://discuss.elastic.co/t/metricset-audit-kernel-is-not-registered-module-not-found/119353/7 "2022-11-04T05:13:34Z")

</div>


