Curious, does the Auditbeat auditd module have a space_left, admin_space_left or disk_full action like auditd does?
If my disk starts filling up I need syslog to start logging that I am running out of space, and if the disk fills up I need to system to halt.
Auditd currently does this but does Auditbeat? I see it has a failure_mode for kernel running out of memory.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.