To forward Audit logs using auditbeat:
Install auditbeat package by executing the below command:
curl -Ls | sudo bash -s -- --client_id "<clientid>" --collector_ip "<collectorip>" --collector_port "12514"
Note: This package holds pre-defined audit rules as per the audit recommendations.