# Unable to see combined auditbeat, filebeat indicies in elastic

**URL:** <https://discuss.elastic.co/t/unable-to-see-combined-auditbeat-filebeat-indicies-in-elastic/367080>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 25, 2024, 4:19am UTC](https://discuss.elastic.co/t/unable-to-see-combined-auditbeat-filebeat-indicies-in-elastic/367080 "2024-09-25T04:19:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhautik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhautik/32/137843_2.png) [@bhautik](https://discuss.elastic.co/u/bhautik)\
**Post date:** [September 25, 2024, 4:19am UTC](https://discuss.elastic.co/t/unable-to-see-combined-auditbeat-filebeat-indicies-in-elastic/367080/1 "2024-09-25T04:19:41Z")

</div>

I am using filebeat, and auditbeat to collect the log and send it to Elastic, here is my config file

```yaml
filebeat.inputs:
  - type: filestream
    id: auditbeat
    fields:
      auditbeat: true
    paths:
      - /var/log/auditbeat/*
    parsers:
      - ndjson:
          target: ""
          overwrite_keys: true

filebeat.autodiscover:
  providers:
    - type: kubernetes
      node: ${NODE_NAME}
      hints.enabled: true
      hints.default_config:
        type: filestream
        id: kubernetes-container-logs-${data.kubernetes.node.name}-${data.kubernetes.pod.name}-${data.kubernetes.container.id}-${data.kubernetes.pod.uid}
        paths:
          - /var/log/containers/*-${data.kubernetes.container.id}.log
        parsers:
          - container: ~
        prospector:
        scanner:
          fingerprint.enabled: false
          symlinks: false
        file_identity.fingerprint: ~
        clean_removed: true

output.elasticsearch:
  hosts: ["${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}"]
  compression_level: 9
  indices:
    - index: "auditbeat-%{[agent.version]}-%{+yyyy.MM.dd}"
      when.equals:
        fields.auditbeat: true
    - index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"
      when.not.equals:
        fields.auditbeat: true

setup.template.enabled: true
setup.template.name: "filebeat"
setup.template.pattern: "filebeat-*"
setup.ilm.enabled: true
setup.ilm.mode: auto

```

I can see the auditbeat Indices but not filebeat Indices to elastic, what am I doing wrong?

thanks.

---

<div class="post-metadata">

**Author:** ![bhautik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhautik/32/137843_2.png) [@bhautik](https://discuss.elastic.co/u/bhautik)\
**Post date:** [September 26, 2024, 1:01pm UTC](https://discuss.elastic.co/t/unable-to-see-combined-auditbeat-filebeat-indicies-in-elastic/367080/2 "2024-09-26T13:01:51Z")

</div>

> [@Filebeat Fails to Process Symlinked Log Files Despite Symlink Configuration Enabled](https://discuss.elastic.co/t/filebeat-fails-to-process-symlinked-log-files-despite-symlink-configuration-enabled/367159):
>
> I am encountering an issue with Filebeat where it fails to process symlinked log files, even though I have configured the symlink handling to be enabled. Below are the details of my configuration and the error messages I’m receiving. filebeat.autodiscover: providers: - type: kubernetes node: ${NODE\_NAME} hints.enabled: true hints.default\_config: type: filestream id: kubernetes-container-logs-${data.kubernetes.node.name}-${data.kubernetes.pod.name}-${data.…
