Auditbeat
Auditbeat is a log shipper for audit data that contains configurable modules that can consume data from a bunch of sources:
- Audit framework via
auditd
(Linux-only) - File integrity monitors filesystem change events (all platforms)
- System (beta):
host
login
package
process
socket
user