Can someone explain what will happen or why it's recommended to turn auditd off? I am currently running with both on and all seems fine but don' want to move to production and find out something is going to crash.
Read through the description of socket_type on the docs page you linked above.
To run the two simultaneously you must use the multicast socket_type in Auditbeat and you must not set any audit_rules in your Auditbeat config (they will be managed by auditd).
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.