-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Auditbeat] Update auditbeat ECS mappings #18596
[Auditbeat] Update auditbeat ECS mappings #18596
Conversation
Pinging @elastic/siem (Team:SIEM) |
💚 Build SucceededExpand to view the summary
Build stats
Test stats 🧪
Steps errorsExpand to view the steps failures
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM assuming the tests go green.
* Update auditbeat ECS mappings * Add changelog entry * Rev go-libaudit with build tag fix (cherry picked from commit bd7414d)
…ngle-modules * upstream/master: [Auditbeat] Update auditbeat ECS mappings (elastic#18596)
What does this PR do?
This is the spiritual successor to #18028 -- with the code to do the categorization itself moved into
go-libaudit
(see elastic/go-libaudit#62).It adds in ECS categorization fields for a good chunk of auditd-based syscalls and event types.
Checklist
CHANGELOG.next.asciidoc
orCHANGELOG-developer.next.asciidoc
.Related issues