Hi Team,
We are seeing that auditbeat service is using lot of memory in our VM's , we suspect that when elasticsearch cluster is down its taking more memory in auditbeat to buffer the data. Could you please let me know if we can do some update in auditbeat.yml so that it will not buffer any data in memory
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
20849 root 20 0 27.4g 24.6g 38784 S 71.4 44.1 683:48.32 auditbeat