Skip to content

Parse more fields from elasticsearch audit log#10385

Merged
ycombinator merged 3 commits intoelastic:6.xfrom
ycombinator:fb-es-audit-log-more-fields-6x
Jan 29, 2019
Merged

Parse more fields from elasticsearch audit log#10385
ycombinator merged 3 commits intoelastic:6.xfrom
ycombinator:fb-es-audit-log-more-fields-6x

Conversation

@ycombinator
Copy link
Copy Markdown
Contributor

@ycombinator ycombinator commented Jan 29, 2019

Follow up to #10352 per #10352 (comment):

While working on this PR I realized that we don't have sample lines for the structured elasticsearch audit log containing a request body (which is supposed to be parsed into the http.request.body.content field). I'm working with @albertzaharovits to get such a sample and will incorporate it into follow up PRs (for master and 6.x).

Accordingly, this PR adds sample lines to the structured and unstructured log file test fixtures for the elasticsearch/audit fileset and teaches the fileset to parse any new fields encountered in these sample lines.

@ycombinator ycombinator changed the title [WIP] Parse more fields from elasticsearch audit log Parse more fields from elasticsearch audit log Jan 29, 2019
@ycombinator ycombinator requested a review from ruflin January 29, 2019 02:36
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/stack-monitoring

@ycombinator ycombinator merged commit 7207729 into elastic:6.x Jan 29, 2019
@ycombinator ycombinator deleted the fb-es-audit-log-more-fields-6x branch December 25, 2019 11:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants