# Unable to start Auditbeat container on Docker

**URL:** <https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [February 26, 2018, 12:16pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481 "2018-02-26T12:16:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![antwan](https://avatars.discourse-cdn.com/v4/letter/a/dbc845/32.png) [@antwan](https://discuss.elastic.co/u/antwan)\
**Post date:** [February 26, 2018, 12:16pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481/1 "2018-02-26T12:16:59Z")

</div>

I have tried this in both CentOS 7 and RHEL Atomic Host. Using ansible, I use the following, with the params containing valid values:

```
docker_container:
name: auditbeat
image: "{{ auditbeat_image }}:{{ auditbeat_version }}"
hostname: "{{ ansible_fqdn }}"
pull: yes
state: started
volumes: "{{ auditbeat_all_volumes }}"
privileged: true
pid_mode: host
command: auditbeat -e -c /etc/auditbeat/auditbeat.yml

```

And end up with:

```
[centos@beats-anha-node2 ~]$ sudo docker logs -f auditbeat
2018-02-26T11:54:17.466Z	INFO	instance/beat.go:468	Home path [/usr/share/auditbeat] Config path: [/usr/share/auditbeat] Data path: [/usr/share/auditbeat/data] Logs path: [/usr/share/auditbeat/logs]
2018-02-26T11:54:17.473Z	INFO	instance/beat.go:475	Beat UUID: 2a85d2d2- 19ef-45c0-90d9-8e80492144d6
2018-02-26T11:54:17.473Z	INFO	instance/beat.go:213	Setup Beat: auditbeat; Version: 6.2.2
2018-02-26T11:54:17.474Z	INFO	fileout/file.go:76	Initialized file output. path=/tmp/auditbeat/output max_size_bytes=10485760 max_backups=7 permissions=-rw-------
2018-02-26T11:54:17.474Z	INFO	pipeline/module.go:76	Beat name: beats-anha-node2.beans.io
2018-02-26T11:54:17.476Z	INFO	[auditd]	auditd/audit_linux.go:65	auditd module is running as euid=0 on kernel=3.10.0-693.11.6.el7.x86_64
2018-02-26T11:54:17.477Z	ERROR	instance/beat.go:667	Exiting: 1 error: 1 error: failed to create audit client: failed to get audit status: failed sending request: connection refused

```

Using the following config(generated from yaml):

```
[centos@beats-anha-node2 ~]$ cat /etc/auditbeat/auditbeat.yml 
auditbeat.modules:
- {audit_rules: '-a always,exit -F arch=b32 -S all -F key=32bit-abi

-a always,exit -F arch=b64 -S execve,execveat -k exec

-a always,exit -F arch=b64 -S accept,bind,connect -F key=external-access

-w /etc/group -p wa -k identity

-w /etc/passwd -p wa -k identity

-w /etc/gshadow -p wa -k identity

-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at
-F exit=-EACCES -k access

-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at
-F exit=-EPERM -k access

', backlog_limit: 8196, failure_mode: silent, module: auditd, rate_limit: 0, resolve_ids: true}
- module: file_integrity
paths: [/bin, /usr/bin, /sbin, /usr/sbin, /etc]
name: beats-anha-node2.beans.io 
output.file: {enable: true, filename: output, path: /tmp/auditbeat}
processors: {add_cloud_metadata: null, add_docker_metadata: null, add_locale: null}

```

I saw that Luq had the same error in his log.[Luq's Thread](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-lxc-container/119913) Since I run as privileged, and using `pid_mode: host` I was thinking it should work.

---

<div class="post-metadata">

**Author:** ![antwan](https://avatars.discourse-cdn.com/v4/letter/a/dbc845/32.png) [@antwan](https://discuss.elastic.co/u/antwan)\
**Post date:** [February 27, 2018, 3:07pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481/2 "2018-02-27T15:07:41Z")

</div>

Trying to follow Running on Docker using a config I have created from yaml for my native installation of Auditbeat, which works perfectly.

```
[centos@beats-anha-node1 ~]$ sudo docker run --pid=host -v /etc/auditbeat/auditbeat.yml:/usr/share/auditbeat/auditbeat.yml docker.elastic.co/beats/auditbeat:6.2.2
2018-02-27T15:05:52.954Z	INFO	instance/beat.go:468	Home path: [/usr/share/auditbeat] Config path: [/usr/share/auditbeat] Data path: [/usr/share/auditbeat/data] Logs path: [/usr/share/auditbeat/logs]
2018-02-27T15:05:52.957Z	INFO	instance/beat.go:475	Beat UUID: 8422f1ad-bdd6-4c84-bf38-41a85fc4d2d8
2018-02-27T15:05:52.957Z	INFO	instance/beat.go:213	Setup Beat: auditbeat; Version: 6.2.2
2018-02-27T15:05:55.958Z	INFO	add_cloud_metadata/add_cloud_metadata.go:297	add_cloud_metadata: hosting provider type not detected.
2018-02-27T15:05:55.959Z	ERROR	instance/beat.go:667	Exiting: error initializing publisher: error initializing processors: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
Exiting: error initializing publisher: error initializing processors: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
[centos@beats-anha-node1 ~]$ cat /etc/auditbeat/auditbeat.yml
auditbeat.modules:
- {audit_rules: '-a always,exit -F arch=b32 -S all -F key=32bit-abi

-a always,exit -F arch=b64 -S execve,execveat -k exec

-a always,exit -F arch=b64 -S accept,bind,connect -F key=external-access

-w /etc/group -p wa -k identity

-w /etc/passwd -p wa -k identity

-w /etc/gshadow -p wa -k identity

-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at
-F exit=-EACCES -k access

-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at
-F exit=-EPERM -k access

', backlog_limit: 8196, failure_mode: silent, module: auditd, rate_limit: 0, resolve_ids: true}
- module: file_integrity
paths: [/bin, /usr/bin, /sbin, /usr/sbin, /etc]
name: beats-anha-node1.beans.io
output.file: {enable: true, filename: output, path: /tmp/auditbeat}
processors:
- {add_cloud_metadata: null}
- {add_locale: null}
- {add_docker_metadata: null}

```

My docker-colleague asks out loudly why Auditbeat inside the container would want to talk to the Docker daemon?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 1, 2018, 3:03am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481/3 "2018-03-01T03:03:28Z")

</div>

Is this a docker-compose config you are showing above? If so, pid\_mode doesn't look correct. Here's an example for Auditbeat: [https://github.com/elastic/stack-docker/blob/3fb05538483c94bd0bd9bd480bb5c0cfd1f8df79/docker-compose.yml#L48-L56](https://github.com/elastic/stack-docker/blob/3fb05538483c94bd0bd9bd480bb5c0cfd1f8df79/docker-compose.yml#L48-L56)

> [@antwan](#):
>
> My docker-colleague asks out loudly why Auditbeat inside the container would want to talk to the Docker daemon?

This is because you have configured the [`add_docker_metadata` processor](https://www.elastic.co/guide/en/beats/auditbeat/6.2/add-docker-metadata.html). This processor connects to socket to receive docker events. It then uses this information to enrich events with information about the associated container. For example if an `execve` happens inside a container then the event will have the container id, name, and labels.

---

<div class="post-metadata">

**Author:** ![antwan](https://avatars.discourse-cdn.com/v4/letter/a/dbc845/32.png) [@antwan](https://discuss.elastic.co/u/antwan)\
**Post date:** [March 1, 2018, 8:54am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481/4 "2018-03-01T08:54:43Z")

</div>

The above is just an ansible-task starting up a docker container, using the syntax from [http://docs.ansible.com/ansible/latest/docker\_container\_module.html#docker-container](http://docs.ansible.com/ansible/latest/docker_container_module.html#docker-container)

Ahh, ok, I was playing around with the config, but I can see how that would cause Auditbeat to want to ask docker stuff..

I will clean up the conf and try again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:15am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-container-on-docker/121481/5 "2022-11-04T05:15:09Z")

</div>


