Kaudit service use 100% CPU core

I have centos 7.9 OS with Postgrep 9.4 DB, i am facing issue with kaudit.service is use 100% cpu core.

After kill kaudit process system working fine.

systemd: auditbeat.service: main process exited, code=exited, status=1/FAILURE
systemd: Unit auditbeat.service entered failed state.
systemd: auditbeat.service failed.
systemd: auditbeat.service holdoff time over, scheduling restart.
systemd: Stopped Audit the activities of users and processes on your system…
systemd: Started Audit the activities of users and processes on your system.
systemd-logind: Removed session 9790.
uditbeat: 2024-07-20T17:30:16.354+0530#011INFO#011instance/beat.go:686#011Home path: [/usr/share/auditbeat] Config path: [/e
tc/auditbeat] Data path: [/var/lib/auditbeat] Logs path: [/var/log/auditbeat] Hostfs Path: [/]

Standard disclaimer: CentOS Linux 7.9 is EOL and will not be receiving any more updates. People using the operating system should be looking to transition to an operating system which has active updates.

That aside, this doesn’t look like an issue with packages which were shipped with CentOS 7 at all. auditbeat is part of elastic tooling and why it is causing a problem with CentOS will need help from people versed in that. I would check to see what version of auditbeat is installed with rpm -q auditbeat and make sure that it is meant to work with CentOS 7 and not for a newer version of an Enterprise Linux like 8 or 9. [Those would be from Alma, Oracle, Red Hat, Rocky or other vendors.]

Similar discussions which might help

2 Likes

@pradeepsingh or a moderator - could you untag most of the CentOS tags on this post? They are not relevant to those topics at all

Removed centos-board, centos-docs, centos-integration-sig, centos-sigs, red-hat-cpe