# Auditbeat starts losing events couple minutes after restart

**URL:** <https://discuss.elastic.co/t/auditbeat-starts-losing-events-couple-minutes-after-restart/191032>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [July 17, 2019, 2:40pm UTC](https://discuss.elastic.co/t/auditbeat-starts-losing-events-couple-minutes-after-restart/191032 "2019-07-17T14:40:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nickbabkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickbabkin/32/57493_2.png) [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Post date:** [July 17, 2019, 2:40pm UTC](https://discuss.elastic.co/t/auditbeat-starts-losing-events-couple-minutes-after-restart/191032/1 "2019-07-17T14:40:51Z")

</div>

Hi everyone!  
We have an incredibly high amount of events lost shown as "auditbeat show auditd-status" command output on some hosts. Example:

auditbeat show auditd-status  
enabled 1  
failure 0  
pid 1893  
rate\_limit 0  
backlog\_limit 8192  
lost 26038486  
backlog 0  
backlog\_wait\_time 0  
features 0x7

Problem appears to come up some time after starting the service. Auditbeat runs with 0 backlog for a while, then 10-20 minutes after backlog starts to grow, reaches 8192 limit which leads to events being dropped until service is restarted again. Restart always helps for some time.

Anyone could guide me on performance tuning or explain reasons for such a significant amount of lost events? Can it be a logstash/elastic performance issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2019, 2:40pm UTC](https://discuss.elastic.co/t/auditbeat-starts-losing-events-couple-minutes-after-restart/191032/2 "2019-08-07T14:40:52Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
