I would advise to turn off rules that audits network activity. It's very expensive. We're working on a better way to monitor network activity for Auditbeat that does not utilize the audit framework.
@andrewkroh... auditing network connections like the rule you described isn't part of the CIS benchmarks. But even if it was, it wouldn't explain why auditbeat takes 50x more CPU than auditd using the same ruleset.
How do I troubleshoot performance issues with auditbeat?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.