The hard link syscalls (link and linkat) do not seem to be configured properly and do not get the same treatment as other file calls.
If no one is currently working on it, I am happy to provide a pr to add them to go-libaudit/aucoalesce/normalizations.yaml
I've already tested a modified version with an extra block similar to symlink and the resulting output from auditbeat seems consistent and works well with my downstream pipeline.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.