Hi everyone,
to collect auditd logs from /var/log/audit.log, I just add TA-auditd and removed standard unix TA. the default TA-auditd does not have any inputs.conf file.
there are no logs i check with
index=* sourcetype= linux:audit
whereas I can see in _internal index that events are coming.
↧