Auditbeat do not delete correctly


I noticed that deleting auditbeat with the parameter (backspressure_strategy:kernel) audit rules continue to work. There are events from them in dmesg.

How to remove auditbeat using (backspressure_strategy:kernel) properly?
How to do this without restarting the system?

I found a ticket with this problem, but it is close

