auditd often creats a lot of disk IO, will it be reduced by auditbeat?
Auditbeat sends data directly to Elasticsearch whereas auditd writes it to disk, so yes, you should see much less disk usage with Auditbeat.
auditd often creats a lot of disk IO, will it be reduced by auditbeat?
Auditbeat sends data directly to Elasticsearch whereas auditd writes it to disk, so yes, you should see much less disk usage with Auditbeat.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.