Thanks for the explanation.
Do I get it right: The elastic-agent auditd integration is using the filebeat auditd module under the hood and not the auditbeat auditd module?
Is there a documentation of what the elastic-agent integrations are doing and what beats they replace? For example, it seems that the elastic-agent "Windows" integration is using auditbeat? But is it also installing sysmon?