Skip to content

Commit

Permalink
Add back in user.effective.* fields to auditd integrations due to no …
Browse files Browse the repository at this point in the history
…longer using experimental schema
  • Loading branch information
Andrew Stucki committed Jan 26, 2021
1 parent 0879f85 commit 8c8012f
Show file tree
Hide file tree
Showing 6 changed files with 140 additions and 2 deletions.
21 changes: 21 additions & 0 deletions auditbeat/_meta/fields.common.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,27 @@
type: keyword
description: Audit user name.

- name: effective
type: group
description: Effective user information.
fields:
- name: id
type: keyword
description: Effective user ID.
- name: name
type: keyword
description: Effective user name.
- name: group
type: group
description: Effective group information.
fields:
- name: id
type: keyword
description: Effective group ID.
- name: name
type: keyword
description: Effective group name.

- name: filesystem
type: group
description: Filesystem user information.
Expand Down
48 changes: 48 additions & 0 deletions auditbeat/docs/fields.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -2722,6 +2722,54 @@ type: keyword
--
[float]
=== effective
Effective user information.
*`user.effective.id`*::
+
--
Effective user ID.
type: keyword
--
*`user.effective.name`*::
+
--
Effective user name.
type: keyword
--
[float]
=== group
Effective group information.
*`user.effective.group.id`*::
+
--
Effective group ID.
type: keyword
--
*`user.effective.group.name`*::
+
--
Effective group name.
type: keyword
--
[float]
=== filesystem
Expand Down
2 changes: 1 addition & 1 deletion auditbeat/include/fields.go

Large diffs are not rendered by default.

48 changes: 48 additions & 0 deletions filebeat/docs/fields.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -523,6 +523,54 @@ type: keyword
Name of the group.


type: keyword

--

[float]
=== effective

Effective user information.


*`user.effective.id`*::
+
--
Effective user ID.

type: keyword

--

*`user.effective.name`*::
+
--
Effective user name.

type: keyword

--

[float]
=== group

Effective group information.


*`user.effective.group.id`*::
+
--
Effective group ID.

type: keyword

--

*`user.effective.group.name`*::
+
--
Effective group name.

type: keyword

--
Expand Down
21 changes: 21 additions & 0 deletions filebeat/module/auditd/_meta/fields.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,27 @@
description: >
Name of the group.
- name: effective
type: group
description: Effective user information.
fields:
- name: id
type: keyword
description: Effective user ID.
- name: name
type: keyword
description: Effective user name.
- name: group
type: group
description: Effective group information.
fields:
- name: id
type: keyword
description: Effective group ID.
- name: name
type: keyword
description: Effective group name.

- name: filesystem
type: group
fields:
Expand Down
2 changes: 1 addition & 1 deletion filebeat/module/auditd/fields.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

0 comments on commit 8c8012f

Please sign in to comment.