elastic / beats

:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
https://www.elastic.co/products/beats
Other
108 stars 4.93k forks source link

[Auditbeat] Prepare System Package to be GA #33765

Open andrewkroh opened 2 years ago

andrewkroh commented 2 years ago

Describe the enhancement:

We previously had plans to deprecate the system.package dataset because in within the Elastic ecosystem we expected that osquerybeat could provide this data using various tables like rpm_package and deb_packages. However, because it cannot provide deltas between previous state and current state the data is not that useful on its own. So we want to improve the Auditbeat system.package dataset such that it can be supported as GA feature and exposed through Elastic Agent.

Describe a specific use case for the enhancement or feature:

References

elasticmachine commented 2 years ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

elasticmachine commented 9 months ago

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)