This is the meta issue for the release of the first version of the Auditbeat system module.
Further tasks are tracked in the backlog issue.
General
1. Host
2. Process
3. Socket
4. User
Main PRs (no longer maintained)
#8356 (MERGED - Rename sysinfo module to system)
#8436 (MERGED - Add host, packages, and processes metricsets)
#8835 (MERGED - Add user metricset)
#8834 (MERGED - Socket metricset)
#9139 (MERGED - Update process metricset)
#9362 (MERGED - Add CI testing)
#9421 (MERGED - Update host metricset)
#9461 (MERGED - Opt-in to detecting password changes)
#9483 (MERGED - Add message field)
#9512 (MERGED - System module documentation)
#9546 (MERGED - Add system module)
This is the meta issue for the release of the first version of the Auditbeat system module.
Further tasks are tracked in the backlog issue.
General
host.idfor darwin (done: Implement UniqueID on Darwin go-sysinfo#31)message(done: [Auditbeat] Add message field to system module #9483)fields.ecs.yml(Add Auditbeat system module fields to fields.ecs.yml #9318)auditbeatandx-pack/auditbeat(done: Add CI testing to x-pack/auditbeat #9362)feature-auditbeat-host(done: [Auditbeat] Add system module #9546)1. Host
2. Process
process, implement scheduled state reporting, and change to single documents (merged: [Auditbeat] Update process metricset #9139)3. Socket
4. User
/etc/shadowopt-in, and do multiple rounds of SHA-512 hashing (done: [Auditbeat] Opt-in to detecting password changes #9461)Main PRs (no longer maintained)
#8356 (MERGED - Rename sysinfo module to system)
#8436 (MERGED - Add host, packages, and processes metricsets)
#8835 (MERGED - Add user metricset)
#8834 (MERGED - Socket metricset)
#9139 (MERGED - Update process metricset)
#9362 (MERGED - Add CI testing)
#9421 (MERGED - Update host metricset)
#9461 (MERGED - Opt-in to detecting password changes)
#9483 (MERGED - Add message field)
#9512 (MERGED - System module documentation)
#9546 (MERGED - Add system module)