Project reference ↗

Auditbeat collects security-relevant activity from the machines running your applications. Depending on its configuration, it can report Linux audit events or detect changes to important files such as binaries and configuration. Teams use those records to investigate unexpected activity and feed monitoring or alerting systems. This is host-level evidence: it is different from the Kubernetes API audit log that records requests to change cluster resources.

Deployment and operating notes

The recovered stable/auditbeat package is historical. Elastic still documents running Auditbeat on Kubernetes as a DaemonSet for file-integrity monitoring and links to Beats deployment through Elastic Cloud on Kubernetes. That evidence establishes a current documented route, not that this site validated every Auditbeat module on every node operating system.

Choose the collection mechanism according to the required signal. File-integrity events, Linux audit events and Kubernetes API audit logs are different sources and should not be presented as interchangeable. Inspect host filesystem mounts, capabilities, node coverage and persistent registry data before deployment. Lock the Beat version to a compatible Elastic Stack and review credentials and transport security. During migration, compare a controlled file change or audit action at the source with the indexed event and alert. Avoid running two collectors against the same destination without understanding duplication and state tracking. Keep audit records outside ephemeral pods, and test behavior during node replacement rather than judging success only by a green DaemonSet.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Preserved for context. Commands, versions, prices and results below reflect the original research.

Auditbeat is a lightweight shipper to audit the activities of users and processes on your systems, so that you can identify potential security policy violations.

You can use Auditbeat to collect audit events from the Linux Audit Framework. You can also use Auditbeat for file integrity check, that is to detect changes to critical files, like binaries and configuration files.

 

Sources & further reading

  1. Elastic Auditbeat on Kubernetes
  2. Recovered historical source (Common Crawl index)

Spotted something that needs another look?

Help improve this page →