Hi,
I am using auditd module in Filebeat to send the audit logs to Logstash. Do I still need to parse the audit logs in Logstash? When I sent the output to elasticsearch everything was working fine but whenswitched to Logstash it is not parsing the data.
is there a auditd module configuration file available just like syslog (link is below)?
https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html
Thanks,
Charan