I think the auditd module does not expect the leading node=X.
It expects to find the logs beginning at type=. With auditd you can control the behavior by setting name_format in your auditd.conf. The default is None IIRC and this causes auditd not to include node=.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.