auditbeat
« Back to VersTracker
Description:
Lightweight Shipper for Audit Data
Type: Formula  |  Latest Version: 9.2.2@0  |  Tracked Since: Dec 17, 2025
Links: Homepage  |  @elastic  |  formulae.brew.sh
Category: Security
Tags: security monitoring audit elasticsearch devops compliance
Install: brew install auditbeat
About:
Auditbeat is a lightweight data shipper that collects system audit data and sends it to Elasticsearch or Logstash for analysis. It monitors system activity such as file changes, user logins, and process execution to enhance security visibility. It provides a low-overhead solution for real-time security monitoring and compliance auditing.
Key Features:
  • Real-time system activity monitoring
  • File integrity monitoring capabilities
  • Low resource overhead
  • Seamless integration with Elastic Stack
  • Pre-built detection rules
Use Cases:
  • Security incident detection and response
  • Compliance auditing and regulatory reporting
  • File integrity monitoring for critical system files
  • User behavior analytics and threat detection
Alternatives:
  • osquery – osquery provides SQL-based querying of system state, while Auditbeat focuses on continuous data streaming to the Elastic Stack
  • auditd – auditd is the Linux kernel audit framework; Auditbeat can collect from auditd but provides easier setup and built-in visualization
  • wazuh – Wazuh is a broader security platform; Auditbeat is lighter and more focused on data collection for the Elastic ecosystem
Version History
Detected Version Rev Change Commit
Dec 2, 2025 4:57pm 0 VERSION_BUMP be449659
Nov 11, 2025 1:52pm 0 VERSION_BUMP 6175b762
Oct 23, 2025 4:19pm 0 VERSION_BUMP 7eebffb1
Sep 13, 2025 12:38pm 0 VERSION_BUMP 1da1ec69
Dec 14, 2024 9:10pm 0 VERSION_BUMP 78971767
Dec 12, 2024 4:13pm 0 VERSION_BUMP 9fe5a5d1
Nov 12, 2024 7:03pm 0 VERSION_BUMP 80f34dee
Nov 12, 2024 6:26pm 0 VERSION_BUMP b2c75c53
Nov 12, 2024 12:26pm 0 VERSION_BUMP 82d51fa5
Oct 26, 2024 8:27pm 0 VERSION_BUMP e9401a39
Sep 26, 2024 6:52pm 0 VERSION_BUMP 35e6c393
Sep 26, 2024 6:25pm 0 VERSION_BUMP 093fe9b7