Auditbeat - 120% CPU?

Also seen userland cpu spinning after a while in auditbeat with socket dataset enabled, will try without as well...

I'm failing to restart auditbeat 7.8.0 with -httpprof :8888 added to the argument list:

DAEMON_ARGS="-httpprof :8888 ..."

root# service auditbeat restart
 * Restarting Auditbeat is a lightweight shipper for audits.
 auditbeat                                                     Error: unknown flag: --httpprof
  auditbeat test config [flags]

  -h, --help   help for config

Global Flags:
  -E, --E setting=value              Configuration overwrite
  -c, --c string                     Configuration file, relative to path.config (default "auditbeat.yml")
  -d, --d string                     Enable certain debug selectors
  -e, --e                            Log to stderr and disable syslog/file output
      --environment environmentVar   set environment the Beat is run in (default default)
      --path.config string           Configuration path string             Data path
      --path.home string             Home path
      --path.logs string             Logs path
      --plugin pluginList            Load additional plugins
      --strict.perms                 Strict permission checking on config files (default true)
  -v, --v                            Log at INFO level


This may seem silly but I'm not able to upload a binary here, it's only allowing images. I can host it on another service and link it if you'd like.

You might find a bit of similar info from the metricbeat' system.socket module

1 Like

I upgraded one system running auditbeat 7.6.1 (without socket issue) to auditbeat 7.8.0 and am getting high CPU usage. I had to disable the socket dataset to workaround.

@hazardousmonk you can upload it somewhere else and send it to me via private msg if you prefer.

@btnrsec can you provide a profile as suggested in Auditbeat - 120% CPU? ?

(Im the OP)

Definitely seeing the high CPU usage of auditbeat. Im having to kill it on a regular basis now.

Im running auditbeat-7.8.0-1.x86_64

@ethrbunny @btnrsec @stefws @hazardousmonk @mgotechlock @BenB196

We've identified the issue with 7.8.0 and have a fix PR.

Here's a snapshot build of 7.8.1 with the fix in the above PR:

Can you give it a try (with socket dataset enabled) and share the outcome?


I've installed it on a few systems. It will be a few days before I can tell whether it's behaving properly.

1 Like

So far so good.

The auditbeat snapshot seems much better than the original.

7.8.0 is a v problematic release. I have nodes dropping out on a regular basis - something I've never seen before in the years I've been using elastic.

Looking forward to 7.8.1+

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.