# High CPU usage for auditbeat

**URL:** <https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [May 27, 2018, 8:30pm UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430 "2018-05-27T20:30:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gbmzjy](https://avatars.discourse-cdn.com/v4/letter/g/ea666f/32.png) [@gbmzjy](https://discuss.elastic.co/u/gbmzjy)\
**Post date:** [May 27, 2018, 8:30pm UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/1 "2018-05-27T20:30:21Z")

</div>

Hi, I am trying to use auditbeat to collect Linux Audit log and send them to our elasticsearch server.  
In order to compare performance with auditd, I tried the following configuration:

auditbeat.modules:

-module: auditd  
audit\_rules: |  
-a always,exit -F arch=b64 -S all -k exec

-module: file\_integrity  
paths:  
-/bin  
-/usr/bin  
-/sbin  
-/usr/sbin  
-/etc

output.file:  
path: "/tmp/auditbeat"  
filename: auditbeat

With the same configuration for auditd, I found that auditbeat has much higher CPU usage. In particular, auditbeat takes above 14% CPU usage while auditd take maximum 5%. The auditd version is auditbeat-6.2.4-amd64.

Are there any ways to reduce the CPU usages as auditd?

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [May 28, 2018, 3:56am UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/2 "2018-05-28T03:56:56Z")

</div>

I think your audit rule is too broad, `-S all` without further filtering will capture ALL syscalls made by all processes. This can easily generate thousands of events per second and is hardly what you want. The common usage for `-S all` is pairing it with `-F arch=b32` so that the usage of a 32-bit API is flagged.

Try narrowing down your rules to something more manageable. The example rules in the configuration are a good start.

As the difference in performance between auditbeat and auditd, note that auditd just writes the raw events to a log file. Auditbeat does plenty of post-processing to present the events in a meaningful way that can be further analyzed in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![dsv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsv/32/47173_2.png) [@dsv](https://discuss.elastic.co/u/dsv)\
**Post date:** [July 15, 2020, 12:11pm UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/3 "2020-07-15T12:11:01Z")

</div>

Have the same problem.  
Auditbeat system module consumes about 12% average of the Intel(R) Xeon(R) CPU E5-2695 v3 @ 2.30GHz.  
This is a huge amount for a prod server. It's to expensive to use it in prod.  
Have to say auditbeat "audit" module consumes about 3% even with a huge set of syscalls monitoring.  
But why does auditbeat "system" module consume such an amount of CPU?  
It looks like non optimized algorithm in software...

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 15, 2020, 1:17pm UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/4 "2020-07-15T13:17:33Z")

</div>

@dsv, there's been some CPU issues with the `system` module at least in 7.7 and 7.8.0. Which version are you running?

Do you observe one of the logical CPUs going to 100% usage or is the load distributed between all CPUs?

---

<div class="post-metadata">

**Author:** ![dsv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsv/32/47173_2.png) [@dsv](https://discuss.elastic.co/u/dsv)\
**Post date:** [July 16, 2020, 6:54am UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/5 "2020-07-16T06:54:17Z")

</div>

auditbeat-7.8.0-1 (x86\_64)

---

<div class="post-metadata">

**Author:** ![dsv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsv/32/47173_2.png) [@dsv](https://discuss.elastic.co/u/dsv)\
**Post date:** [July 16, 2020, 7:09am UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/6 "2020-07-16T07:09:42Z")

</div>

I don't know how to determine if 1 core used or not.  
Every 10s CPU utilization jumps from 0 to ~102% and corresponding TIME in top utility increases to about 1s by every spike.  
If i add the "-socket" option utilization sometimes spikes to 200%.  
I changed the "-period" from 10s to 60s and this is temporary workaround for me (load is about 4%).  
But i see the auditbeat configuration with 60s "- period" sometimes after restart consumes about 20% (average).  
And the unstable behavior of the CPU load doesn't allow me still to deploy auditbeat in production.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 16, 2020, 10:40am UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/7 "2020-07-16T10:40:04Z")

</div>

You can see for example using `htop -p $(pidof auditbeat)`.

Anyway, I suggest you try the custom 7.8.0 snapshot build in this post:

> [@Auditbeat - 120% CPU?](https://discuss.elastic.co/t/auditbeat-120-cpu/234909/28):
>
> @ethrbunny @btnrsec @stefws @hazardousmonk @mgotechlock @BenB196 We've identified the issue with 7.8.0 and have a [fix PR.](https://github.com/elastic/beats/pull/19764) Here's a snapshot build of 7.8.1 with the fix in the above PR: [https://drive.google.com/drive/folders/1V704wdgKaIKCci0aO1Bao8COAHhjKotp?usp=sharing](https://drive.google.com/drive/folders/1V704wdgKaIKCci0aO1Bao8COAHhjKotp?usp=sharing) Can you give it a try (with socket dataset enabled) and share the outcome? Thanks

If it solves the problem, this fix will be released in the upcoming 7.8.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:24am UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430/8 "2022-11-04T05:24:12Z")

</div>


