Osquerybeat: Result values type translation#25012
Merged
urso merged 7 commits intoelastic:masterfrom Apr 14, 2021
Merged
Conversation
Contributor
💔 Build Failed
Expand to view the summary
Build stats
Test stats 🧪
Trends 🧪Steps errors
Expand to view the steps failures
|
| Test | Results |
|---|---|
| Failed | 0 |
| Passed | 46994 |
| Skipped | 5134 |
| Total | 52128 |
Contributor
|
Pinging @elastic/agent (Team:Agent) |
Contributor
|
This pull request is now in conflicts. Could you fix it? 🙏 |
james-elastic
approved these changes
Apr 12, 2021
… the first time the osquery integration is activated
Contributor
Author
urso
reviewed
Apr 14, 2021
|
|
||
| if c.log == nil { | ||
| c.log = logp.NewLogger(logTag) | ||
| } |
There was a problem hiding this comment.
nit; new code should not use NewLogger. The logger should be assumed to be a dependency that must be passed in.
urso
approved these changes
Apr 14, 2021
mergify bot
pushed a commit
that referenced
this pull request
Apr 14, 2021
Translates Osquery results values to appropriate type according to the column type information of the query. Utilizes the GetQueryColumns osquery go client API, caches the types information per query in LRU cache. (cherry picked from commit bcf6c92) # Conflicts: # NOTICE.txt # go.mod
urso
pushed a commit
that referenced
this pull request
Apr 14, 2021
v1v
added a commit
to v1v/beats
that referenced
this pull request
Apr 15, 2021
* upstream/master: packer cache support for the 7.x and 7.latestMinor branches (elastic#25091) Remove EventFetcher and EventsFetcher interface (elastic#25093) Update go-structform to 0.0.8 (elastic#25051) Update copy_fields.asciidoc (elastic#25053) [elastic-agent] ensure container is backwards compatible (elastic#25092) Add --fleet-server-service-token. Rename --fleet-server to --fleet-server-es. (elastic#25083) Add cgroup.cpuacct percentages (elastic#25057) Add tests for truncated and symlinked files in filestream input (elastic#24425) Fix panic when Hearbeat monitor initialization fails twice (elastic#25073) [Filebeat][httpjson] Change append transform to initiate new fields as a slice (elastic#25074) Osquerybeat: Result values type translation (elastic#25012) Update Osquerybeat spec to get it downloading from the correct artifactory path (elastic#25076) Fix changelog (elastic#25079) Strip Azure EventHub connection string in debug logs (elastic#25066) Change googlecloud to gcp in field names (elastic#25038) Bump stack version to 7.12.0 for testing (elastic#24957) packer-cache: cache the existing docker images on ARM and some more (elastic#25068) Disable logstash TestFetch flaky test (elastic#25044)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What does this PR do?
Translates Osquery results values to appropriate type according to the column type information of the query.
Utilizes the GetQueryColumns osquery go client API, caches the types information per query in LRU cache.
Why is it important?
Primarily allows us to handle better the numeric values that were strings by default.
Checklist
CHANGELOG.next.asciidocorCHANGELOG-developer.next.asciidoc.How to test this PR locally
Can test with standalone Osquerybeat config, example:
Or running with agent and fleet server.
Related issues
Related issues
Screenshots
osquery mapping:

collected osquery data with types converted appropriately with osquerybeat
