Start your 14-day free trial today

No Credit Card Required

Try Free

Already have an account? Sign In

Send data via Auditbeat to your Logstash instance provided by


A log shipper designed for audit data.

Auditbeat is an open source shipping agent that lets you ship audit data to one or more destinations, including Logstash.

Step 1 - Install AuditbeatCopy

deb (Debian/Ubuntu/Mint)

curl -L -O
sudo dpkg -i -oss-7.15.1-amd64.deb

rpm (CentOS/RHEL/Fedora)

curl -L -O
sudo rpm -vi -oss-7.15.1-x86_64.rpm


curl -L -O
tar xzvf -oss-7.15.1-darwin-x86_64.tar.gz


  • Download and extract the Windows zip file.
  • Rename the -<version>-windows directory to ``.
  • Open a PowerShell prompt as an Administrator.
  • Run the following to install as a Windows service:
If script execution is disabled on your system, you need to set the execution policy for the current session to allow the script to run. For example: PowerShell.exe -ExecutionPolicy UnRestricted -File .\install-service-.ps1.
My OS isn't here! Chat to support now

Step 2 - Configure ModulesCopy

Locate and open the auditbeat configuration file:

  • deb/rpm (Debian/Ubuntu/Mint/CentOS/RHEL/Fedora): /etc/auditbeat/auditbeat.yml
  • Windows: C:\Program Files\auditbeat\auditbeat.yml
  • Mac: <EXTRACTED_ARCHIVE>/auditbeat.yml

By default, the file_integrity module will be enabled. This module watches for file changes such as when a file is created, updated or deleted. When a change is detected, auditbeat will send events containing metadata to one or more configured output sources (e.g. Logstash).

The module can be configured in auditbeat.yml by adding or removing path addresses. Auditbeat will watch for changes in files relative to these paths.

There is also a full example configuration file called auditbeat.reference.yml that shows all the possible options.

Step 3 - Configure outputCopy

We'll be shipping to Logstash so that we have the option to run filters before the data is indexed.
Comment out the elasticsearch output block.

## Comment out elasticsearch output
#  hosts: ["localhost:9200"]
No input available! Your stack is missing the required input for this data source Talk to support to add the input

Step 4 - Validate configurationCopy

Let's check the configuration file is syntactically correct by running directly inside the terminal. If the file is invalid, will print an error loading config file error message with details on how to correct the problem.


sudo  -e -c /etc//.yml


./ -e -c .yml


.\.exe -e -c .yml

Step 5 - Start auditbeatCopy

If we now start the Auditbeat service, any audited changes will be shipped to your hosted Logstash instance.


sudo systemctl enable auditbeat
sudo systemctl start auditbeat




Start-Service auditbeat

Try changing a file located in one of the configured directory paths. You should see a change event in Kibana.

Step 6 - how to diagnose no data in StackCopy

If you don't see data appearing in your Stack after following the steps, visit the Help Centre guide for steps to diagnose no data appearing in your Stack or Chat to support now.

Step 7 - Auditbeat Logging OverviewCopy

Auditbeat is one of the most recent additions to Elastic Stack’s Beats. It is primarily used to gather audit data on user activity and processes running on your server’s infrastructure. Additionally, Auditbeat can be used to detect crucial and unexpected changes to configuration files & binaries.

This can be key to helping you to identify compliance issues and security violations in your organisation. Once configured, changes to the file are updated in real-time to your output, allowing for optimised visibility of security-related instances. It can be used directly to undertake these processes & gather data without the need to access Linux’s Auditd.

Centralising your Auditbeat event data using a log management system such as provides a way of easily managing your ELK Stack overheads in one single platform.

If you need any further assistance with migrating your Auditbeat data to Logstash we're here to help you get started. Feel free to reach out by contacting our support team by visiting our dedicated Help Centre or via live chat & we'll be happy to assist.

Toggle View

Expand View

Return to Search

© 2023 Ltd, All rights reserved.