Hi,
Does someone know what is time sequence that auditbeat is getting events from auditd?
Is it possible to reduce this time?
I made some testing if auditbeat is logging reboot commands for server - unsuccessfully. With same rules auditd is successfully log reboot command.
Thanks and best regards,
Luka