Back to Beats

Start Auditbeat [auditbeat-starting]

docs/reference/auditbeat/auditbeat-starting.md

9.4.01.7 KB
Original Source

Start Auditbeat [auditbeat-starting]

Before starting Auditbeat:

To start Auditbeat, run:

:::::::{tab-set}

::::::{tab-item} DEB

sh
sudo service auditbeat start

Also see Auditbeat and systemd. ::::::

::::::{tab-item} RPM

sh
sudo service auditbeat start

Also see Auditbeat and systemd. ::::::

::::::{tab-item} MacOS

sh
sudo chown root auditbeat.yml <1>
sudo ./auditbeat -e
  1. You’ll be running Auditbeat as root, so you need to change ownership of the configuration file, or run Auditbeat with --strict.perms=false specified. See Config File Ownership and Permissions. ::::::

::::::{tab-item} Linux

sh
sudo chown root auditbeat.yml <1>
sudo ./auditbeat -e
  1. You’ll be running Auditbeat as root, so you need to change ownership of the configuration file, or run Auditbeat with --strict.perms=false specified. See Config File Ownership and Permissions. ::::::

::::::{tab-item} Windows

sh
PS C:\Program Files\auditbeat> Start-Service auditbeat

By default Windows log files are stored in C:\Program Files\Auditbeat-Data\logs.

:::{note} In versions before 9.0.6, the default location for Windows log files was C:\ProgramData\auditbeat\logs. ::: ::::::

:::::::