Auditbeat chroot jail support

Hi All,

I was wondering if there is any documentation on getting Auditbeat to collect information from chroot jails? Based on how chroot jails work, it doesn't seem like there is a straight forward way of getting Auditbeat to collect their logs/actions. I wasn't able to find anything on the forums or Google. So I'd figure I'd ask here to see if anyone has any ideas on getting this to work.

I've moved your post to the SIEM category so Auditbeat developers can find your post.

