Beats auditbeat

Elastic · Elastic.Auditbeat

Collect your Linux audit framework data and monitor the integrity of your files.

winget install --id Elastic.Auditbeat --exact --source winget

Latest 9.3.3

Release Notes

Features and enhancements All

  • Update OTel Collector components to v0.148.0. #49578 Filebeat
  • Add retry back-off logic to streaming input CrowdStrike follower. #48542 #46072
  • Add secret_state config to CEL input for encrypted storage of secrets accessible as state.secret. #49207 Add a secret_state configuration field to the CEL input. When configured in a Fleet integration package with secret: true, the values are stored encrypted by Fleet. At runtime, the contents are placed at state.secret and unconditionally redacted in debug logs. The key secret in the plain-text state configuration is reserved and rejected by validation to prevent accidental unencrypted storage of values intended to be secret.
  • Allow string and number arrays in httpjson chained configurations. #49391 #16662
  • Add support for URL and URL query parsing and formatting in the Streaming input CEL environment. #49653 #17875 Metricbeat
  • Add client secret authentication support to Azure App Insights module. #48880 Fixes Elastic Agent
  • Fix an issue that could delay reporting shutdown of Agent components. #49414 #49388
  • Reduce AutoOps logging from info to debug for polling. #49507 #49506 Filebeat
  • Fix Filestream take_over causing file re-ingestion when used with autodiscover. #49632 #49579
  • Fix compatibility of the Journald input with journald/systemd versions < 242. #49445 #48152
  • Add rate-limit backoff to CrowdStrike streaming input oauth2 transport. #49453 Wrap the oauth2 HTTP transport used by the CrowdStrike falcon streaming input with a rate-limit-aware transport that intercepts 429 responses, reads the Retry-After header, and backs off before retrying. This prevents the oauth2 token refresh from generating a burst of unauthorized requests that triggers CrowdStrike's 15-per-minute rate limit. The discover endpoint also returns a retry-after hint to the session-level retry loop as a minimum wait floor.
  • Skip request tracer path validation when tracing is disabled to prevent input startup failures. #49655 The startup path validation in cel, httpjson, http_endpoint, and entity analytics inputs checked whether the tracer config struct was non-nil rather than whether tracing was enabled. Integration package templates always include a tracer block (with enabled defaulting to false), so the struct is never nil. Under the agentless/otel runtime the relative tracer path resolves outside the permitted directory, causing all affected inputs to fail immediately even though tracing was disabled. The config-level Validate methods already used the correct enabled() guard; the startup paths now do the same.
  • Fix Filebeat crash loop when running under Elastic Agent and taking too long to initialise. #49796 #49512 Libbeat
  • Fix a bug where escaped characters in syslog structured data caused an EOF error. #49392 #43944 Metricbeat
  • Fix unnecessary Windows filesystem metricset errors from non-existent volumes. #49553 Fix an issue where filesystem metric collection on Windows could report errors for volumes that are no longer present. Update to gosigar v0.14.4. Winlogbeat
  • Skip record ID gap detection for forwarded Windows events. #49819

Installer type: wix

Architecture Scope Download SHA256
x64 Download D8E44D51286BEB636F45C60D680F7E9E834C9764E61891DAE4D783C36C965819

Details

Homepage
https://www.elastic.co/downloads/beats/auditbeat
License
Elastic-2.0
Publisher
Elastic
Support
https://github.com/elastic/beats/issues
Privacy Policy
https://www.elastic.co/legal/privacy-statement
Copyright
© 2026. Elasticsearch B.V. All Rights Reserved

Older versions (18)

9.3.2
Architecture Scope Download SHA256
x64 Download BC74889F662610549C790429CAD22E81636ADF6BE1F2DCF1F9D4707FC0409FCC
9.3.1
Architecture Scope Download SHA256
x64 Download 77DC76BE56FC2847EADCCF4026CF14028D270AF3BC431E0F46102F957A029C74
9.3.0
Architecture Scope Download SHA256
x64 Download 1967D2B66D24B31B85638061D29E9ED82ADFBAA2BED6B3CFF0EC8F99BC0AA036
9.2.4
Architecture Scope Download SHA256
x64 Download 0E972B036F460EB093A4F95E46C267174F5BB99E05F75A3802DFB59B43E7383E
9.2.3
Architecture Scope Download SHA256
x64 Download 430B95CEB31702C0842BCE7D0210C913EB8986F43BE3A6674CC29DC601318E63
9.2.2
Architecture Scope Download SHA256
x64 Download 57B4B08EB97065EC581CB086BF455544B2D4DFE939748B22F74828A12646C363
9.2.1
Architecture Scope Download SHA256
x64 Download DB2D8ED95A9860F366F4F49B6117664E510250DBB9C3EDA1F271B06D10946337
9.2.0
Architecture Scope Download SHA256
x64 Download E7A0D0B2E445EB5185F64559E1298F0B3CF28E4EB912E6BEB1C28812F01AA59D
9.1.5
Architecture Scope Download SHA256
x64 Download 29865383906E1B3AB40F311A9658A94DD2BA9B14F649BEDA4534D3BC073EB9F8
9.1.4
Architecture Scope Download SHA256
x64 Download 7EEDE3A206733144918623043392E5DE581ED1BD1906FC19ACA0CFD038DC5DF9
9.1.3
Architecture Scope Download SHA256
x64 Download AEE1A6721B8CE82BE3D32815759013B58784EDFE9A59263207DDCD9DFD4EC047
9.1.1
Architecture Scope Download SHA256
x64 Download 9DE31BD644C8728FEE6B02B246EAB163410BD2EF248CBFD1240F0DE9E9F214AA
9.1.0
Architecture Scope Download SHA256
x64 Download 684268C831BF12CD923B40B78D37AE7BDDF1C431AC7838E1A86B9BA54553EE7C
9.0.4
Architecture Scope Download SHA256
x64 Download 123CFB612B4F18EA309AC850CBA8A1C1363181AA4EE982A1D3DD2E7281A54894
9.0.3
Architecture Scope Download SHA256
x64 Download DF7C141E326136FBD07F1F6530BB63A179130EA0903D4B067E9C2263D7F9CCC2
9.0.2
Architecture Scope Download SHA256
x64 Download 98D2B99C21ACB39B8BEFE0827FDD584653DAE8598B641605875FE82AE1319986
9.0.1
Architecture Scope Download SHA256
x64 Download 9508B562483EBE3DA2687590C878E1AC067937EFF51C920E7C3698C79681BA55
9.0.0
Architecture Scope Download SHA256
x64 Download 0D9BD3913537011DA37EDF45C7AEB5F3B191F1FF871C85CDE2C8B4F93F2E4859