As of now the SEKOIA Agent runs only on Windows operating systems. In order to support as much environment as possible, adding support to linux OSes is a necessary step.
Netlink should be used directly so auditd won't be a dependency and the produced log must be formatted under the ECS format.
By default the agent doesn't have to setup auditd or configure it. However it would be nice if the agent could setup the appropriate auditd config so the user doesn't have to configure it to be able to collect its logs.