# Unable to start auditbeat on docker

**URL:** <https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [May 21, 2018, 4:05am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609 "2018-05-21T04:05:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![obudiman](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@obudiman](https://discuss.elastic.co/u/obudiman)\
**Post date:** [May 21, 2018, 4:05am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/1 "2018-05-21T04:05:46Z")

</div>

Hi, I've been trying to deploy the official auditbeat:6.2.4 container on our centos 7.4 but I'm stuck with the following error log:

> 2018-05-21T03:53:08.825Z INFO instance/beat.go:468 Home path: [/usr/share/auditbeat] Config path: [/usr/share/auditbeat] Data path: [/usr/share/auditbeat/data] Logs path: [/usr/share/auditbeat/logs]  
> 2018-05-21T03:53:08.825Z DEBUG [beat] instance/beat.go:495 Beat metadata path: /usr/share/auditbeat/data/meta.json  
> 2018-05-21T03:53:08.825Z INFO instance/beat.go:475 Beat UUID: 0bd41a5d-0893-4d51-9ffc-1a4d1eb95fa6  
> 2018-05-21T03:53:08.825Z INFO instance/beat.go:213 Setup Beat: auditbeat; Version: 6.2.4  
> 2018-05-21T03:53:08.825Z DEBUG [beat] instance/beat.go:230 Initializing output plugins  
> 2018-05-21T03:53:08.825Z DEBUG [processors] processors/processor.go:49 Processors:  
> 2018-05-21T03:53:08.825Z INFO elasticsearch/client.go:145 Elasticsearch url: [http://10.4.95.242:9200](http://10.4.95.242:9200)  
> 2018-05-21T03:53:08.826Z INFO pipeline/module.go:76 Beat name: 84e65b21e37f  
> 2018-05-21T03:53:08.826Z DEBUG [modules] beater/metricbeat.go:80 Register [ModuleFactory:, MetricSetFactory:[auditd/auditd, file\_integrity/file]]  
> 2018-05-21T03:53:08.826Z DEBUG [processors] processors/processor.go:49 Processors:  
> 2018-05-21T03:53:08.826Z INFO [auditd] auditd/audit\_linux.go:65 auditd module is running as euid=0 on kernel=3.10.0-693.el7.x86\_64  
> 2018-05-21T03:53:08.826Z ERROR instance/beat.go:667 Exiting: 1 error: 1 error: failed to create audit client: failed to get audit status: failed sending request: connection refused  
> Exiting: 1 error: 1 error: failed to create audit client: failed to get audit status: failed sending request: connection refused

I have disabled the auditd,

> ● auditd.service - Security Auditing Service  
> Loaded: loaded (/usr/lib/systemd/system/auditd.service; disabled; vendor preset: enabled)  
> Active: inactive (dead) since Mon 2018-05-21 13:05:56 AEST; 58min ago  
> Docs: man:auditd(8)  
> [GitHub - linux-audit/audit-documentation: Documentation and specifications](https://github.com/linux-audit/audit-documentation)  
> Main PID: 707 (code=exited, status=0/SUCCESS)

I've also used the following params to start the container as suggested,

> docker run -d --name sandbox\_auditbeat --privileged --pid=host -v /tmp/auditbeat.yml:/usr/share/auditbeat/auditbeat.yml [docker.elastic.co/beats/auditbeat:6.2.4](http://docker.elastic.co/beats/auditbeat:6.2.4)

As seen from the output above, the kernel is 3.10 which means the unicast socket type is used so it should work just fine as long as we have disabled the auditd; doesn't seem to be the case here.

The auditbeat.yml,

> ```
> auditbeat.modules:
> - module: auditd
> audit_rules: |
> -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -k access
> -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -k access
> fields:
> tenant: abc
> setup.kibana:
> host: "10.4.95.244:5601"
> output.elasticsearch:
> hosts: ["10.4.95.242:9200"]
> username: "elastic"
> password: "changeme"
> logging.level: debug
> 
> ```

What else could I've missed here?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 21, 2018, 12:17pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/2 "2018-05-21T12:17:48Z")

</div>

If you also have auditd installed on this box, can you trying running `sudo auditctl -s` and `sudo auditctl -l` on this box and report the output?

What OS is this? Is it a custom kernel build?

There are couple reasons for "connection refused" (aka `ECONNREFUSED)` that I could find from various sources.

- The `ECONNREFUSED` error can [indicate](https://github.com/linux-audit/audit-userspace/blob/07933a0c638e09deb46b6a9a5e4aba696ca87325/src/auditctl.c#L402-L403) that the kernel has the audit system disabled.
- It can [indicate](https://github.com/torvalds/linux/blob/9eda2d2dca830f0f8923b1f377d0fb70f576af1d/kernel/audit.c#L1008-L1020) that the process is running in a different user namespace.

---

<div class="post-metadata">

**Author:** ![obudiman](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@obudiman](https://discuss.elastic.co/u/obudiman)\
**Post date:** [May 21, 2018, 11:19pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/3 "2018-05-21T23:19:09Z")

</div>

Here's the output

> [root@xxx ~]# auditctl -s  
> enabled 1  
> failure 1  
> pid 0  
> rate\_limit 0  
> backlog\_limit 8192  
> lost 228  
> backlog 0  
> loginuid\_immutable 0 unlocked  
> [root@xxx ~]# auditctl -l  
> No rules

It's a standard CentOS 7.4,

> [root@xxx ~]# cat /etc/redhat-release  
> CentOS Linux release 7.4.1708 (Core)  
> [root@xxx ~]# uname -a  
> Linux xxx.domain 3.10.0-693.el7.x86\_64 #1 SMP Tue Aug 22 21:09:27 UTC 2017 x86\_64 x86\_64 x86\_64 GNU/Linux

I can see the auditd output just fine when it is enabled so it shouldn't be the kernel I reckon. I've installed the auditbeat directly onto the OS instead of using the official container and it runs just fine apparently. So it must've been something to do with the docker/image setting?

As for the namespace, I've already put the "--pid=host" option and set privilege mode to it as instructed on the [manual](https://www.elastic.co/guide/en/beats/auditbeat/6.0/running-on-docker.html) which should have addressed the user namespace issue.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 21, 2018, 11:47pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/4 "2018-05-21T23:47:15Z")

</div>

It looks like you have done all the right things AFAICT. I don't see anything obvious in the kernel sources for v3.10.0 (though I didn't look at the patches applied by RH) that would cause ECONNREFUSED. What about looking in the logs. Is there anything related in `dmesg` from the kernel?

Not sure if this command works in the journald version on Centos 7, but is there anything interesting in `sudo journalctl -af _TRANSPORT=audit`?

---

<div class="post-metadata">

**Author:** ![obudiman](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@obudiman](https://discuss.elastic.co/u/obudiman)\
**Post date:** [May 22, 2018, 12:11am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/5 "2018-05-22T00:11:47Z")

</div>

The commands work but there's really nothing that relates. Nothing comes up when I started the container.

Just to reiterate, when I installed the auditbeat directly on the host (instead of container), it works just fine. There's no error messages whatsoever.

Only when I use the official container then it fails,

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 29, 2018, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/6 "2018-05-29T14:27:38Z")

</div>

I'm running into this problem as well.

Host OS: Centos - Linux 3.10  
Docker container: Centos - Linux 3.10  
Auditbeat 6.2.4  
I'm running with --cap-add=ALL --pid=host and --privileged

Auditbeat runs fine on the host. When I try to run Auditbeat in a container I get this error:

Exiting: 1 error: 1 error: failed to create audit client: failed to get audit status: failed sending request: connection refused

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 29, 2018, 2:30pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/7 "2018-05-29T14:30:30Z")

</div>

It looks like there's no official Auditbeat image that we can use. Is that correct?

I didn't see an Auditbeat image here:

> **[elastic/beats-docker](https://github.com/elastic/beats-docker)**
>
> beats-docker - Official Beats Docker images

Is there a known reason why it may not work in Docker?

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 29, 2018, 3:10pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/8 "2018-05-29T15:10:09Z")

</div>

It looks like it's failing in audit\_linux.go right here :

// process be in initial PID namespace).  
status, err := ms.client.GetStatus()

I run it with --cap-add=AUDIT\_CONTROL and --pid=host so it seems it should work.

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 29, 2018, 4:16pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/9 "2018-05-29T16:16:23Z")

</div>

I added --net=host and then got a slightly different error:

operation not permitted

It looks like there's some permission error. I'll investigate further.

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 29, 2018, 7:40pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/10 "2018-05-29T19:40:47Z")

</div>

It works if I run as root and --net=host.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:23am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-docker/132609/11 "2022-11-04T05:23:36Z")

</div>


