Auditd logs are quite noisy. Looking into parsing this logs into a SIEM (AzSentinel) and filtering out some of this noise for monitoring. I have seen some articles on logging based on RecordType_s however, does it not make sense to monitor based on the key? i.e key_s. any ideas?