# Queue.disk not working with auditbeat

**URL:** <https://discuss.elastic.co/t/queue-disk-not-working-with-auditbeat/366012>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [September 4, 2024, 9:14am UTC](https://discuss.elastic.co/t/queue-disk-not-working-with-auditbeat/366012 "2024-09-04T09:14:45Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joshua\_Koch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_koch/32/137300_2.png) [@Joshua\_Koch](https://discuss.elastic.co/u/Joshua_Koch)\
**Post date:** [September 4, 2024, 9:14am UTC](https://discuss.elastic.co/t/queue-disk-not-working-with-auditbeat/366012/1 "2024-09-04T09:14:45Z")

</div>

According to these instructions, the disk queue should work with auditbeat.  
`beats/auditbeat/current/configuring-internal-queue.html`

According to the documentation, the folder defined under path should be created when the service is started.  
Even if the elastic host is no longer accessible, only the RAM is used as a queue.  
I use Rocky Linux (9.4) and auditbeat (8.15) in the latest version.

Config example:

```yaml
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["xxx.xxx:9200/"]

  # Performance preset - one of "balanced", "throughput", "scale",
  # "latency", or "custom".
  preset: balanced

  # Protocol - either `http` (default) or `https`.
  #protocol: "https"

  # Authentication credentials - either API key or username/password.
  #api_key: "id:api_key"
  username: "auditbeat"
  password: "xxxxx"

  # Anzahl der Ereignisse pro Batch.
  bulk_max_size: 2048

  # Anzahl der Ereignisse pro Batch.
  workers: 4

# ----------------------------------- Buffer -----------------------------------
#queue.mem:
# events: 4096
# flush.min_events: 512
# flush.timeout: 5s

queue.disk:
  max_size: 10GB
  path: "/var/lib/auditbeat/diskqueue"

```
