All in one Install Filebeats vs. what's listed in tutorial

114 views
Skip to first unread message

Steven Wegner

unread,
Apr 4, 2022, 4:57:37 PM4/4/22
to Wazuh mailing list
New to Wazuh. I tried searching for a similar question but havent found an answer. 

I have used the all in one installation and have everything up and running. I wanted to use a module ( panw) and used the "Add Data" from the Kibana Overview section in Wazuh . The instruction references "   /etc/filebeat/modules.d/panw.yml" However I do not have that file in /modules.d

The tutorial also says to download filebeat from :
artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.10.2-x86_64.rpm

Looking at that RPM I see a module directory, but no modules.d directory. Further the module directory lists many many modules including the one I am looking for. 
 Why the discrepancy? Do I infact follow the tut and download rpm? I think that might break things. 
Many thanks,

elw...@wazuh.com

unread,
Apr 5, 2022, 3:25:34 AM4/5/22
to Wazuh mailing list
Hello,

The default installation of Wazuh is using Filebeat OSS which does not have that specific module available. You may want to use the installation using Elastic Basic described here https://documentation.wazuh.com/current/installation-guide/more-installation-alternatives/elastic-stack/all-in-one-deployment/all-in-one.html.

Hope it helps.

Regards,
Wali

Steven Wegner

unread,
Apr 5, 2022, 7:07:48 PM4/5/22
to Wazuh mailing list
Thank you, Wali. That was it. I now have the module I wanted to be enabled. Still not working, but I'll post that error separately if I cant figure it out. Thanks again!
Reply all
Reply to author
Forward
0 new messages