and after cooking the CPU at 100% for a while these were the logs. It's worth noting that the auditbeat process took a very long time to stop when using systemctl. During this exercise (of logging), the process refused to shutdown once. The process was refusing to terminate even with the 'kill' command as root. I had to use the SIGKILL to stop it.
Summary
Jun 23 21:31:06 host auditbeat[32484]: 2020-06-23T21:31:06.458Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":34},"beat":{"cpu":{"system":{"ticks":5380,"time":{"ms":280}},"total":{"ticks":1291040,"time":{"ms":25856},"value":1291040},"user":{"ticks":1285660,"time":{"ms":25576}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1411271}},"memstats":{"gc_next":15914128,"memory_alloc":16507464,"memory_total":528722600,"rss":1081344},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":39,"batches":4,"total":39}},"pipeline":{"clients":8,"events":{"active":0,"published":39,"total":39},"queue":{"acked":39}}},"metricbeat":{"auditd":{"auditd":{"events":6,"success":6}},"system":{"host":{"events":1,"success":1},"user":{"events":32,"success":32}}},"system":{"load":{"1":1.78,"15":0.99,"5":1.29,"norm":{"1":1.78,"15":0.99,"5":1.29}}}}}}
Jun 23 21:31:36 host auditbeat[32484]: 2020-06-23T21:31:36.474Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":51},"beat":{"cpu":{"system":{"ticks":5620,"time":{"ms":244}},"total":{"ticks":1319960,"time":{"ms":28928},"value":1319960},"user":{"ticks":1314340,"time":{"ms":28684}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1441288}},"memstats":{"gc_next":15595952,"memory_alloc":13150280,"memory_total":541558632,"rss":-1687552},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":79,"batches":6,"total":79}},"pipeline":{"clients":8,"events":{"active":0,"published":79,"total":79},"queue":{"acked":79}}},"metricbeat":{"auditd":{"auditd":{"events":9,"success":9}},"system":{"process":{"events":70,"success":70}}},"system":{"load":{"1":1.63,"15":1.01,"5":1.31,"norm":{"1":1.63,"15":1.01,"5":1.31}}}}}}
Jun 23 21:32:06 host auditbeat[32484]: 2020-06-23T21:32:06.461Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":129},"beat":{"cpu":{"system":{"ticks":5670,"time":{"ms":48}},"total":{"ticks":1349660,"time":{"ms":29700},"value":1349660},"user":{"ticks":1343990,"time":{"ms":29652}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1471275}},"memstats":{"gc_next":16736688,"memory_alloc":13694536,"memory_total":549902160,"rss":880640},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":21,"batches":2,"total":21}},"pipeline":{"clients":8,"events":{"active":0,"published":21,"total":21},"queue":{"acked":21}}},"metricbeat":{"auditd":{"auditd":{"events":21,"success":21}}},"system":{"load":{"1":1.38,"15":1,"5":1.28,"norm":{"1":1.38,"15":1,"5":1.28}}}}}}
Jun 23 21:32:36 host auditbeat[32484]: 2020-06-23T21:32:36.477Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":7},"beat":{"cpu":{"system":{"ticks":5710,"time":{"ms":40}},"total":{"ticks":1379040,"time":{"ms":29380},"value":1379040},"user":{"ticks":1373330,"time":{"ms":29340}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1501291}},"memstats":{"gc_next":16736688,"memory_alloc":14598864,"memory_total":555815640},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":1,"batches":1,"total":1}},"pipeline":{"clients":8,"events":{"active":0,"published":1,"total":1},"queue":{"acked":1}}},"metricbeat":{"auditd":{"auditd":{"events":1,"success":1}}},"system":{"load":{"1":1.31,"15":1.01,"5":1.27,"norm":{"1":1.31,"15":1.01,"5":1.27}}}}}}
Jun 23 21:33:06 host auditbeat[32484]: 2020-06-23T21:33:06.463Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":27},"beat":{"cpu":{"system":{"ticks":5760,"time":{"ms":52}},"total":{"ticks":1408840,"time":{"ms":29796},"value":1408840},"user":{"ticks":1403080,"time":{"ms":29744}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1531277}},"memstats":{"gc_next":17286816,"memory_alloc":13684792,"memory_total":562756304,"rss":1114112},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":38,"batches":2,"total":38}},"pipeline":{"clients":8,"events":{"active":0,"published":38,"total":38},"queue":{"acked":38}}},"metricbeat":{"auditd":{"auditd":{"events":5,"success":5}},"system":{"host":{"events":1,"success":1},"user":{"events":32,"success":32}}},"system":{"load":{"1":1.25,"15":1.01,"5":1.26,"norm":{"1":1.25,"15":1.01,"5":1.26}}}}}}
Jun 23 21:33:36 host auditbeat[32484]: 2020-06-23T21:33:36.465Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":102},"beat":{"cpu":{"system":{"ticks":5960,"time":{"ms":192}},"total":{"ticks":1438200,"time":{"ms":29352},"value":1438200},"user":{"ticks":1432240,"time":{"ms":29160}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1561279}},"memstats":{"gc_next":14683280,"memory_alloc":10967280,"memory_total":574967768,"rss":-3178496},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":74,"batches":5,"total":74}},"pipeline":{"clients":8,"events":{"active":0,"published":74,"total":74},"queue":{"acked":74}}},"metricbeat":{"auditd":{"auditd":{"events":16,"success":16}},"system":{"process":{"events":58,"success":58}}},"system":{"load":{"1":1.21,"15":1.01,"5":1.25,"norm":{"1":1.21,"15":1.01,"5":1.25}}}}}}
Jun 23 21:34:06 host auditbeat[32484]: 2020-06-23T21:34:06.460Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":6000,"time":{"ms":48}},"total":{"ticks":1467990,"time":{"ms":29804},"value":1467990},"user":{"ticks":1461990,"time":{"ms":29756}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1591274}},"memstats":{"gc_next":16350672,"memory_alloc":11550824,"memory_total":581640704,"rss":1347584},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":8,"events":{"active":0}}},"system":{"load":{"1":1.12,"15":1.01,"5":1.22,"norm":{"1":1.12,"15":1.01,"5":1.22}}}}}}
Jun 23 21:34:36 host auditbeat[32484]: 2020-06-23T21:34:36.464Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":27},"beat":{"cpu":{"system":{"ticks":6070,"time":{"ms":64}},"total":{"ticks":1497380,"time":{"ms":29380},"value":1497380},"user":{"ticks":1491310,"time":{"ms":29316}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1621279}},"memstats":{"gc_next":15062128,"memory_alloc":11370384,"memory_total":587632768,"rss":-1171456},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":5,"batches":1,"total":5}},"pipeline":{"clients":8,"events":{"active":0,"published":5,"total":5},"queue":{"acked":5}}},"metricbeat":{"auditd":{"auditd":{"events":5,"success":5}}},"system":{"load":{"1":1.07,"15":1.01,"5":1.2,"norm":{"1":1.07,"15":1.01,"5":1.2}}}}}}
Jun 23 21:35:06 host auditbeat[32484]: 2020-06-23T21:35:06.474Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":102},"beat":{"cpu":{"system":{"ticks":6120,"time":{"ms":48}},"total":{"ticks":1527190,"time":{"ms":29808},"value":1527190},"user":{"ticks":1521070,"time":{"ms":29760}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1651287}},"memstats":{"gc_next":15658816,"memory_alloc":11042504,"memory_total":594390552},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":16,"batches":1,"total":16}},"pipeline":{"clients":8,"events":{"active":0,"published":16,"total":16},"queue":{"acked":16}}},"metricbeat":{"auditd":{"auditd":{"events":16,"success":16}}},"system":{"load":{"1":1.04,"15":1,"5":1.18,"norm":{"1":1.04,"15":1,"5":1.18}}}}}}
Jun 23 21:35:36 host auditbeat[32484]: 2020-06-23T21:35:36.473Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received_msgs":27},"beat":{"cpu":{"system":{"ticks":6340,"time":{"ms":224}},"total":{"ticks":1557000,"time":{"ms":29816},"value":1557000},"user":{"ticks":1550660,"time":{"ms":29592}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":40},"info":{"ephemeral_id":"c35e10b7-4c09-4cd9-a939-f77a34421e97","uptime":{"ms":1681287}},"memstats":{"gc_next":14861408,"memory_alloc":12727328,"memory_total":607077720,"rss":548864},"runtime":{"goroutines":61}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":96,"batches":6,"total":96}},"pipeline":{"clients":8,"events":{"active":0,"published":96,"total":96},"queue":{"acked":96}}},"metricbeat":{"auditd":{"auditd":{"events":5,"success":5}},"system":{"host":{"events":1,"success":1},"process":{"events":58,"success":58},"user":{"events":32,"success":32}}},"system":{"load":{"1":1.02,"15":1,"5":1.16,"norm":{"1":1.02,"15":1,"5":1.16}}}}}}