Configuring Auditbeat to only report modifications to files I want to monitor

Okay, this are audit events generated by other processes (pam, sudo, etc.), and they show up even if Auditbeat itself install no rules for them.

To filter them out, the suggestion is to install a drop processor. Have a look at this answer: