[Auditd] Populate process.args array with process arguments#2730
Merged
adriansr merged 4 commits intoelastic:mainfrom Feb 23, 2022
adriansr:auditd_process_args
Merged
[Auditd] Populate process.args array with process arguments#2730adriansr merged 4 commits intoelastic:mainfrom adriansr:auditd_process_args
adriansr merged 4 commits intoelastic:mainfrom
adriansr:auditd_process_args
Conversation
Prevents the indices exceeding the 10,000 field limit due to an arbitrarily large number of aNN fields. This is a combination of the following Filebeat module fixes: - elastic/beats#29601 - elastic/beats#30382
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
efd6
approved these changes
Feb 22, 2022
Contributor
efd6
left a comment
There was a problem hiding this comment.
LGTM after minor issue is fixed.
| @@ -1,4 +1,8 @@ | |||
| # newer versions go on top | |||
| - version: "2.1.0" | |||
| - description: Store EXECVE arguments in process.args array. | |||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Prevents the indices exceeding the 10,000 field limit due to an arbitrarily large number of
auditd.log.aNNNfields.Also removes the unnecessary setter for
event.ingested.Easier to review by looking at each commit independently.
The first one just removes event.original and re-generates logs, which has the annoying side-effect of sorting the generated docs by key, creating a lot of noise.
Checklist
changelog.ymlfile.Related issues
This is a combination of the following Filebeat module fixes: