We tried to disable the plugin i.e. idskerndsp and restarted auditd process to log the audit events to disk. audispd-plugin configuration # cat /etc/audisp/plugins.d/idskerndsp.conf active = no direction = out path = /ux/ids/idskerndsp type = always args = --test format = string Rules Configured # auditctl -l LIST_RULES: exit,always syscall=open,close Audit Status # auditctl -s AUDIT_STATUS: enabled=1 flag=1 pid=20819 rate_limit=0 backlog_limit=320 lost=0 backlog=0 With log_format = RAW, above rule enabled for auditing, time taken is real 2m41.484s user 0m0.028s sys 0m8.789s