Well, "now" is a bit delayed, by a few seconds anyway, while it goes to my input servers (of 2), then goes into rabbitmq, then gets picked up my the elk servers (of 2), to be put into es. ;)
My logstash setup is new from this week, though. :)
Hmmm. So, one more question off the top.
I want to move /var/log/audit/* to another directory, but the audit.log is being kept open.
How so I get it to stop that and start a new log?
Ahh there we go.
systemctl reload auditd ;)