Hello ,
By any chance, has anyone already configured the AUDITBEAT product, from the toolbox?
I made a conf for rhel (x86) but listing under AIX the folders created (/opt/freeware/share/auditbeat/bin/auditbeat, /opt/freeware/share/auditbeat/kibana) and the only 2 files of conf offered (auditbeat.yml and fields.yml), I cannot start the service, nor know where to configure the ip addresses for the elastricsearch server nor the logstash.
The only message I get is a missing or unconfigured module:
/opt/freeware/share/auditbeat/bin #./auditbeat test config
Exiting: 1 error: no metricsets configured for module 'system'
Thanks in advance
Fred
ps : I'd prefer to use the native auditd module, but our partner need to use auditbeat uploads.
------------------------------
Frederic PONCE
------------------------------