# Problem Using Filebeat for logging ssh log in

**URL:** <https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 16, 2021, 10:52am UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412 "2021-02-16T10:52:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Skriix](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Skriix](https://discuss.elastic.co/u/Skriix)\
**Post date:** [February 16, 2021, 10:52am UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412/1 "2021-02-16T10:52:01Z")

</div>

Hi,

SSh logs are not being shown in the kibana, I am pushing my logs to the ES Only

I am using the following configuration,  
OS - Ubuntu 20.04  
ES - 7.11.0  
LogStash - 7.11.0  
Kibana - 7.11.0  
FileBeat - 7.11.0

The enabled module in filebeat is System

System.yml file :

```
- module: system
  # Syslog
  syslog:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:
    var.paths: ["/var/log/messages"]
  # Authorization logs
    var.convert_timezone: true
  auth:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:
    var.paths: ["/var/log/secure"]
    var.convert_timezone: true

```

With the console in kibana i have

```
POST /filebeat-*/_search
{
"size": 10,
"query": {
"match": {
"source": "/var/log/messages"
}
}
}

```

Output :

```
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : [x]
  }
}

```

For

`GET _nodes/stats/ingest`

I have :

```
{
  "_nodes" : {
    "total" : 1,
    "successful" : 1,
    "failed" : 0
  },
  "cluster_name" : "my-application",
  "nodes" : {
    "L_HA_nnGQ9OfQiW-4y4q0w" : {
      "timestamp" : 1613472269331,
      "name" : "node-1",
      "transport_address" : "192.168.1.26:9300",
      "host" : "192.168.1.26",
      "ip" : "192.168.1.26:9300",
      "roles" : [
        "data",
        "data_cold",
        "data_content",
        "data_hot",
        "data_warm",
        "ingest",
        "master",
        "ml",
        "remote_cluster_client",
        "transform"
      ],
      "attributes" : {
        "ml.machine_memory" : "3093676032",
        "xpack.installed" : "true",
        "transform.node" : "true",
        "ml.max_open_jobs" : "20",
        "ml.max_jvm_size" : "1547698176"
      },
      "ingest" : {
        "total" : {
          "count" : 0,
          "time_in_millis" : 0,
          "current" : 0,
          "failed" : 0
        },
        "pipelines" : {
          "filebeat-7.11.0-system-syslog-pipeline" : {
            "count" : 0,
            "time_in_millis" : 0,
            "current" : 0,
            "failed" : 0,
            "processors" : [
              {
                "set" : {
                  "type" : "set",
                  "stats" : {
                    "count" : 0,
                    "time_in_millis" : 0,
                    "current" : 0,
                    "failed" : 0
                  }
                }
              }
"filebeat-7.11.0-system-auth-pipeline" : {
            "count" : 0,
            "time_in_millis" : 0,
            "current" : 0,
            "failed" : 0,
            "processors" : [
              {
                "set" : {
                  "type" : "set",
                  "stats" : {
                    "count" : 0,
                    "time_in_millis" : 0,
                    "current" : 0,
                    "failed" : 0
                  }
                }
              }
```

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [February 16, 2021, 11:59am UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412/2 "2021-02-16T11:59:23Z")

</div>

Please, can you parse your post in markdown? What's the output of filebeat?

---

<div class="post-metadata">

**Author:** ![Skriix](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Skriix](https://discuss.elastic.co/u/Skriix)\
**Post date:** [February 16, 2021, 12:24pm UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412/3 "2021-02-16T12:24:38Z")

</div>

What do you mean by "output of filebeat" ? You want to see my filebeat.yml ?

---

<div class="post-metadata">

**Author:** ![Skriix](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Skriix](https://discuss.elastic.co/u/Skriix)\
**Post date:** [February 16, 2021, 1:10pm UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412/4 "2021-02-16T13:10:11Z")

</div>

I just solve my problem ... because in my system.yml

```
- module: system
  # Syslog
  syslog:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:
    var.paths: ["/var/log/messages"]
  # Authorization logs
    var.convert_timezone: true
  auth:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:
    var.paths: ["/var/log/secure"]
    var.convert_timezone: true

```

My 2 paths were wrong, they doesn't exists in Ubuntu ... So i replace

`var.paths: ["/var/log/messages"]`

by :

`var.paths: ["/var/log/syslog"]`

and

`var.paths: ["/var/log/secure"]`

by

`var.paths: ["/var/log/auth.log"]`

What a mistake 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2021, 3:11pm UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412/5 "2021-03-16T15:11:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
