I am using auditd module in Filebeat to send the audit logs to Logstash. Do I still need to parse the audit logs in Logstash? When I sent the output to elasticsearch everything was working fine but whenswitched to Logstash it is not parsing the data.
is there a auditd module configuration file available just like syslog (link is below)?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.