Linux auditd to ECS mapping

hi
We got data coming via syslog-> logstash from certain Linux devices and don't have auditbeats.
Is there a logstash pattern, where I can map the auditd fields to ECS (common schema) format?