# \#auditbeat

**URL:** https://discuss.elastic.co/tag/auditbeat/59.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Auditbeat Exclusion of Process](https://discuss.elastic.co/t/auditbeat-exclusion-of-process/384243)

<div class="topic-metadata">

**Author:** [@testtest](https://discuss.elastic.co/u/testtest)\
**Replies:** 2\
**Last updated:** [December 27, 2025, 1:31pm UTC](https://discuss.elastic.co/t/auditbeat-exclusion-of-process/384243 "2025-12-27T13:31:27Z")

</div>

Hi All, Could someone help me with exclude any process executable related to this path /usr/local/manageengine/uems\_agent/bin/\* (I can see a lot of incoming logs related to /usr/local/manageengine/uems\_agent/bin/dcpa…

---

## [Auditbeat javascript processor error with v9.2.3](https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188)

<div class="topic-metadata">

**Author:** [@grants](https://discuss.elastic.co/u/grants)\
**Replies:** 2\
**Last updated:** [December 19, 2025, 12:48am UTC](https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188 "2025-12-19T00:48:04Z")

</div>

Any idea what could be wrong with my processor? Version: 9.2.3 Operating System: ubuntu 22.04 LTS Steps to Reproduce: Processor listed below Setting up auditbeat on a new host encountered an error with a config I know…

---

## [How to correctly report VM hostname when Elastic Agent runs in a Podman container](https://discuss.elastic.co/t/how-to-correctly-report-vm-hostname-when-elastic-agent-runs-in-a-podman-container/383336)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 1\
**Last updated:** [November 12, 2025, 11:56am UTC](https://discuss.elastic.co/t/how-to-correctly-report-vm-hostname-when-elastic-agent-runs-in-a-podman-container/383336 "2025-11-12T11:56:23Z")

</div>

Hi everyone, I’m trying to collect package installation/removal events using the system\_audit.package stream on Rocky Linux 9.6. I’m running Elastic Agent 9.1.3 (elastic-agent-complete) inside a Podman container, manag…

---

## [Elastic Agent 9.1.3 – system\_audit.package on Rocky Linux 9.6 – no DNF install/remove events](https://discuss.elastic.co/t/elastic-agent-9-1-3-system-audit-package-on-rocky-linux-9-6-no-dnf-install-remove-events/383289)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 9\
**Last updated:** [November 11, 2025, 1:28pm UTC](https://discuss.elastic.co/t/elastic-agent-9-1-3-system-audit-package-on-rocky-linux-9-6-no-dnf-install-remove-events/383289 "2025-11-11T13:28:10Z")

</div>

Hi, I’m trying to collect package installation/removal events using the system\_audit.package stream on Rocky Linux 9.6. I’m running Elastic Agent 9.1.3 (elastic-agent-complete) in a Podman container. image: \`\`docker.e…

---

## [Memory leak on kubernetes nodes](https://discuss.elastic.co/t/memory-leak-on-kubernetes-nodes/372389)

<div class="topic-metadata">

**Author:** [@dimaz](https://discuss.elastic.co/u/dimaz)\
**Replies:** 17\
**Last updated:** [October 8, 2025, 11:25am UTC](https://discuss.elastic.co/t/memory-leak-on-kubernetes-nodes/372389 "2025-10-08T11:25:15Z")

</div>

Hi, I see memory issue when i'm using Auditbeat on kubernetes nodes. I am trying with Auditbeat 8.12 and 8.13. Here is the config I'm running: auditbeat.modules: - module: auditd processors: - add\_session\_metad…

---

## [Why is beats 8.19.0 latest Version?](https://discuss.elastic.co/t/why-is-beats-8-19-0-latest-version/380592)

<div class="topic-metadata">

**Author:** [@ferdinandweiner](https://discuss.elastic.co/u/ferdinandweiner)\
**Replies:** 2\
**Last updated:** [July 30, 2025, 1:24pm UTC](https://discuss.elastic.co/t/why-is-beats-8-19-0-latest-version/380592 "2025-07-30T13:24:08Z")

</div>

Hello auditbeat team, I noticed that version 8.19.0 has the latest flag on GitHub. However, on the website it is 9.1.0. Is there a specific reason for this, or was the latest flag simply set incorrectly? Thanks, Ferd…

---

## [Ubuntu 24.04 Support](https://discuss.elastic.co/t/ubuntu-24-04-support/371457)

<div class="topic-metadata">

**Author:** [@computersalat](https://discuss.elastic.co/u/computersalat)\
**Replies:** 4\
**Last updated:** [April 15, 2025, 10:35pm UTC](https://discuss.elastic.co/t/ubuntu-24-04-support/371457 "2025-04-15T22:35:05Z")

</div>

Hi, what about compatibility of Auditbeat and Ubuntu 24.04 ? It is sadly not listed in the matrix yet. Thank you for information :slight\_smile:

---

## [Auditbeat tries to manage audit settings if socket\_type: multicast is set](https://discuss.elastic.co/t/auditbeat-tries-to-manage-audit-settings-if-socket-type-multicast-is-set/376188)

<div class="topic-metadata">

**Author:** [@metanot](https://discuss.elastic.co/u/metanot)\
**Replies:** 5\
**Last updated:** [April 14, 2025, 3:08pm UTC](https://discuss.elastic.co/t/auditbeat-tries-to-manage-audit-settings-if-socket-type-multicast-is-set/376188 "2025-04-14T15:08:59Z")

</div>

Hello all, i'm trying to implement hardened installation of auditbeat on host (running not from root, limiting exposed capacities via systemd AmbientCapacities/setcap). Auditbeat version is 8.17 If i use config option s…

---

## [Extracting process environment variables](https://discuss.elastic.co/t/extracting-process-environment-variables/375955)

<div class="topic-metadata">

**Author:** [@rafirs](https://discuss.elastic.co/u/rafirs)\
**Replies:** 0\
**Last updated:** [March 14, 2025, 8:48pm UTC](https://discuss.elastic.co/t/extracting-process-environment-variables/375955 "2025-03-14T20:48:31Z")

</div>

What's the recommended approach to extracting a specific set of environment variables from an event? Failing to find a syntax to reference the fields within process.env, I did find that using a script/javascript process…

---

## [Auditbeat handling of link and linkat syscalls](https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868)

<div class="topic-metadata">

**Author:** [@rafirs](https://discuss.elastic.co/u/rafirs)\
**Replies:** 2\
**Last updated:** [March 14, 2025, 7:44pm UTC](https://discuss.elastic.co/t/auditbeat-handling-of-link-and-linkat-syscalls/375868 "2025-03-14T19:44:55Z")

</div>

The hard link syscalls (link and linkat) do not seem to be configured properly and do not get the same treatment as other file calls. If no one is currently working on it, I am happy to provide a pr to add them to go-li…

---

## [FIM integration User data missing](https://discuss.elastic.co/t/fim-integration-user-data-missing/374170)

<div class="topic-metadata">

**Author:** [@amarasinghe.kaluarac](https://discuss.elastic.co/u/amarasinghe.kaluarac)\
**Replies:** 4\
**Last updated:** [February 10, 2025, 4:10pm UTC](https://discuss.elastic.co/t/fim-integration-user-data-missing/374170 "2025-02-10T16:10:31Z")

</div>

Hi all, I have configured the File Integrity Monitoring Integration for my Linux server but even though the logs being ingested to my Elasticsearch some fileds like Process.user.name is missing from logs , This process …

---

## [Auditbeat-\* index no data showing](https://discuss.elastic.co/t/auditbeat-index-no-data-showing/369950)

<div class="topic-metadata">

**Author:** [@acrme123](https://discuss.elastic.co/u/acrme123)\
**Replies:** 0\
**Last updated:** [November 2, 2024, 8:22pm UTC](https://discuss.elastic.co/t/auditbeat-index-no-data-showing/369950 "2024-11-02T20:22:31Z")

</div>

I installed and followed the instructions to integrate Auditbeat into Kibana. Configured the yml file to output to my elasticsearch host and kibana. using curl I am able to reach it just fine. It created the dashboard an…

---

## [Auditbeat not work in Ubuntu 22.04 after a reboot or shutdown](https://discuss.elastic.co/t/auditbeat-not-work-in-ubuntu-22-04-after-a-reboot-or-shutdown/369785)

<div class="topic-metadata">

**Author:** [@L1ghtsou1](https://discuss.elastic.co/u/L1ghtsou1)\
**Replies:** 6\
**Last updated:** [November 1, 2024, 2:05am UTC](https://discuss.elastic.co/t/auditbeat-not-work-in-ubuntu-22-04-after-a-reboot-or-shutdown/369785 "2024-11-01T02:05:23Z")

</div>

I installed Elasticsearch and Auditbeat service version 8.15.2 for Ubuntu Server 22.04. After host reboot, auditbeat inactive and not send log to ELK node. service auditbeat status ○ auditbeat.service - Audit the activi…

---

## [Impact of not upgrading to 7.17 first](https://discuss.elastic.co/t/impact-of-not-upgrading-to-7-17-first/366630)

<div class="topic-metadata">

**Author:** [@mang0wifi](https://discuss.elastic.co/u/mang0wifi)\
**Replies:** 0\
**Last updated:** [September 16, 2024, 3:21pm UTC](https://discuss.elastic.co/t/impact-of-not-upgrading-to-7-17-first/366630 "2024-09-16T15:21:33Z")

</div>

Please can anyone explain the impact of not upgrading to 7.17 for auditbeat and winlogbeat? I am trying to troubleshoot an ELK stack and the previous team have upgraded from 7.10 straight to 8.12 (even though all the do…

---

## [Auditbeat 7.13.0 vs 8.15.0 logs format](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279)

<div class="topic-metadata">

**Author:** [@Matt\_Pinch](https://discuss.elastic.co/u/Matt_Pinch)\
**Replies:** 3\
**Last updated:** [September 10, 2024, 12:28pm UTC](https://discuss.elastic.co/t/auditbeat-7-13-0-vs-8-15-0-logs-format/366279 "2024-09-10T12:28:55Z")

</div>

Upgrading from auditbeat 7.13.0 -\> 8.15.0. What differences are expected to be seen in the logs? Does 8.15.0 provide the same information as 7.13.0? Does the format change? Is it backward compatible? Thanks.

---

## [Queue.disk not working with auditbeat](https://discuss.elastic.co/t/queue-disk-not-working-with-auditbeat/366012)

<div class="topic-metadata">

**Author:** [@Joshua\_Koch](https://discuss.elastic.co/u/Joshua_Koch)\
**Replies:** 0\
**Last updated:** [September 4, 2024, 9:14am UTC](https://discuss.elastic.co/t/queue-disk-not-working-with-auditbeat/366012 "2024-09-04T09:14:45Z")

</div>

According to these instructions, the disk queue should work with auditbeat. beats/auditbeat/current/configuring-internal-queue.html According to the documentation, the folder defined under path should be created when t…

---

## [Uninstalling beats on Linux does not stop systemd service](https://discuss.elastic.co/t/uninstalling-beats-on-linux-does-not-stop-systemd-service/364560)

<div class="topic-metadata">

**Author:** [@PCChris](https://discuss.elastic.co/u/PCChris)\
**Replies:** 2\
**Last updated:** [August 20, 2024, 2:12pm UTC](https://discuss.elastic.co/t/uninstalling-beats-on-linux-does-not-stop-systemd-service/364560 "2024-08-20T14:12:48Z")

</div>

Uninstalling beats (e.g. auditbeat, metricbeat) on Linux (e.g. RHEL 8.10) does not appear to stop the beat process / systemd service. For RPM packages, I believe this should be handled by the %systemd\_preun macro in the …

---

## [Displays specifically which lines have been changed in the file](https://discuss.elastic.co/t/displays-specifically-which-lines-have-been-changed-in-the-file/364808)

<div class="topic-metadata">

**Author:** [@Erik\_Dito\_Tampubolon](https://discuss.elastic.co/u/Erik_Dito_Tampubolon)\
**Replies:** 6\
**Last updated:** [August 13, 2024, 3:26am UTC](https://discuss.elastic.co/t/displays-specifically-which-lines-have-been-changed-in-the-file/364808 "2024-08-13T03:26:07Z")

</div>

Does auditbeat (file integrity module) make it possible to display modified lines in a file? For example, when I change the content of a file, auditbeat can display at what line the content of the file has been changed. …

---

## [Elastic auditbeat v6 vs v7 unknown TCP connects](https://discuss.elastic.co/t/elastic-auditbeat-v6-vs-v7-unknown-tcp-connects/363516)

<div class="topic-metadata">

**Author:** [@ficco2024](https://discuss.elastic.co/u/ficco2024)\
**Replies:** 1\
**Last updated:** [July 22, 2024, 4:05am UTC](https://discuss.elastic.co/t/elastic-auditbeat-v6-vs-v7-unknown-tcp-connects/363516 "2024-07-22T04:05:10Z")

</div>

Hello, I am seeing unknown TCP connections in auditbeat when processing or publishing events in v6.7 but there is no such unknown connections in v7+. Is it correct old version behavior and what is it used for? Here is …

---

## [Auditbeat: Broken kibana dashboards – missing .keyword in the fields](https://discuss.elastic.co/t/auditbeat-broken-kibana-dashboards-missing-keyword-in-the-fields/361350)

<div class="topic-metadata">

**Author:** [@marcinhlybin](https://discuss.elastic.co/u/marcinhlybin)\
**Replies:** 5\
**Last updated:** [June 18, 2024, 10:19am UTC](https://discuss.elastic.co/t/auditbeat-broken-kibana-dashboards-missing-keyword-in-the-fields/361350 "2024-06-18T10:19:01Z")

</div>

Version: 8.14.0 Operating System: Ubuntu 22.04.4 LTS Steps to Reproduce: Load the dashboards as recommended in the documentation: auditbeat setup -e \\ -E output.logstash.enabled=false \\ -E output.elasticsearch.hos…

---

## [Trunce events problem](https://discuss.elastic.co/t/trunce-events-problem/359455)

<div class="topic-metadata">

**Author:** [@masonlu2014](https://discuss.elastic.co/u/masonlu2014)\
**Replies:** 0\
**Last updated:** [May 14, 2024, 11:47am UTC](https://discuss.elastic.co/t/trunce-events-problem/359455 "2024-05-14T11:47:44Z")

</div>

hello team, we have met auditbeat truncate events probem, would you pls help me share some idea how to fix that ?? \[root@rnotesting auditbeat\]# curl http://23123123214321421fasdsadasdsadasfasfsafagsgdsgsdgxxxxxxxxx1234…

---

## [Auditbeat memory leak in 8.13.0](https://discuss.elastic.co/t/auditbeat-memory-leak-in-8-13-0/357512)

<div class="topic-metadata">

**Author:** [@nemo](https://discuss.elastic.co/u/nemo)\
**Replies:** 25\
**Last updated:** [May 9, 2024, 2:40am UTC](https://discuss.elastic.co/t/auditbeat-memory-leak-in-8-13-0/357512 "2024-05-09T02:40:53Z")

</div>

Hi! I use auditbeat v8.13.0, and the memory grows very large. The auditbeat running on a web server with less requests. Below there's some screen shots:

---

## [Auditbeat does not log all commands executed by users](https://discuss.elastic.co/t/auditbeat-does-not-log-all-commands-executed-by-users/359088)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [May 8, 2024, 6:28pm UTC](https://discuss.elastic.co/t/auditbeat-does-not-log-all-commands-executed-by-users/359088 "2024-05-08T18:28:08Z")

</div>

Hi All, How can I configure auditbeat to log all commands executed by users ? I am asking it because when i execute "echo test" command, it is not logged by auditbeat, but when i execute "/usr/bin/echo test" command, i…

---

## [Sending data to ES via Google Load balancer a good idea?](https://discuss.elastic.co/t/sending-data-to-es-via-google-load-balancer-a-good-idea/358807)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 0\
**Last updated:** [May 6, 2024, 10:24am UTC](https://discuss.elastic.co/t/sending-data-to-es-via-google-load-balancer-a-good-idea/358807 "2024-05-06T10:24:41Z")

</div>

Hi, I'm want to replace my old cluster in AWS with a new one in GCP, while there, I restructured the layout of the cluster a bit, i.e. have separate master and data nodes, and Kibana running on separate hosts, instead r…

---

## [Beat.db grows to 12G Bytes in windows](https://discuss.elastic.co/t/beat-db-grows-to-12g-bytes-in-windows/358070)

<div class="topic-metadata">

**Author:** [@rugang](https://discuss.elastic.co/u/rugang)\
**Replies:** 2\
**Last updated:** [May 3, 2024, 8:17pm UTC](https://discuss.elastic.co/t/beat-db-grows-to-12g-bytes-in-windows/358070 "2024-05-03T20:17:00Z")

</div>

I installed auditbeat in windows (with the windows package). part of the configuration file is as following # =========================== Modules configuration ============================ auditbeat.modules: - module: …

---

## [How to generate events related to Network in Auditbeat Version 8.13.2](https://discuss.elastic.co/t/how-to-generate-events-related-to-network-in-auditbeat-version-8-13-2/358694)

<div class="topic-metadata">

**Author:** [@Wayne435](https://discuss.elastic.co/u/Wayne435)\
**Replies:** 0\
**Last updated:** [May 3, 2024, 9:13am UTC](https://discuss.elastic.co/t/how-to-generate-events-related-to-network-in-auditbeat-version-8-13-2/358694 "2024-05-03T09:13:14Z")

</div>

Hello All, We have Auditbeat Version - 8.13.2 in our Ubuntu. Currently collecting data for all the Modules. Could you please let us know what to add in configuration file to collect below events- -\> accepted-connecti…

---

## [Auditbeat memory usage gradually increases](https://discuss.elastic.co/t/auditbeat-memory-usage-gradually-increases/358600)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [May 2, 2024, 6:27am UTC](https://discuss.elastic.co/t/auditbeat-memory-usage-gradually-increases/358600 "2024-05-02T06:27:17Z")

</div>

Hi, I am running auditbeat-8.12.1 across a number of hosts. After restarting the service, I am seeing the memory usage grow from 0.6% to 13% over a period of 8 hours. It will continue until OOM. I assumed this may be…

---

## [Limit CPU consumptio by auditbeat initial scan](https://discuss.elastic.co/t/limit-cpu-consumptio-by-auditbeat-initial-scan/356847)

<div class="topic-metadata">

**Author:** [@Roberto3](https://discuss.elastic.co/u/Roberto3)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 2:45pm UTC](https://discuss.elastic.co/t/limit-cpu-consumptio-by-auditbeat-initial-scan/356847 "2024-04-05T14:45:05Z")

</div>

Hi, we need to lower the cpu usage by the initial scan done by auditbeat windows agent. it takes up to 20% but for 30 to 60 min and we need to reduce the CPU consumption because is a critical server. Is there a way to r…

---

## [Inotify leak](https://discuss.elastic.co/t/inotify-leak/356080)

<div class="topic-metadata">

**Author:** [@masonlu2014](https://discuss.elastic.co/u/masonlu2014)\
**Replies:** 4\
**Last updated:** [March 28, 2024, 12:58am UTC](https://discuss.elastic.co/t/inotify-leak/356080 "2024-03-28T00:58:36Z")

</div>

hello team, we found auditbeat consumer a lot inotify recently, and we are using the latest auditbeat version We find that auditbeat pods created many inotify instances \> 2000, but most of them are not used, i.e. no i…

---

## [Memory Usage Issues with Auditbeat](https://discuss.elastic.co/t/memory-usage-issues-with-auditbeat/355696)

<div class="topic-metadata">

**Author:** [@hassangongs](https://discuss.elastic.co/u/hassangongs)\
**Replies:** 0\
**Last updated:** [March 19, 2024, 9:36am UTC](https://discuss.elastic.co/t/memory-usage-issues-with-auditbeat/355696 "2024-03-19T09:36:05Z")

</div>

Could you please ask our official developers at Elastic if it's normal for the memory range fluctuation in Auditbeat usage to be between 100MB and 300+MB?

[Next page](https://discuss.elastic.co/tag/auditbeat/59.md?match_all_tags=true&page=1&tags%5B%5D=auditbeat)
