Auditbeat

Auditbeat is a log shipper for audit data that contains configurable modules that can consume data from a bunch of sources:

  • Audit framework via auditd (Linux-only)
  • File integrity monitors filesystem change events (all platforms)
  • System (beta):
    • host
    • login
    • package
    • process
    • socket
    • user