Closed cwurm closed 5 years ago
Pinging @elastic/secops (mostly testing).
fyi, I made a bunch of updates above to reflect the current state
Updated to include only what will be in 6.6. Added new issue for 6.7 / 7.0.
The System module was released with four datasets in 6.6. Closing.
Next releases 6.7 and 7.0 are tracked in https://github.com/elastic/beats/issues/10103.
Backlog in https://github.com/elastic/beats/issues/9344.
This is the meta issue for the release of the first version of the Auditbeat system module.
Further tasks are tracked in the backlog issue.
General
host.id
for darwin (done: https://github.com/elastic/go-sysinfo/pull/31)message
(done: https://github.com/elastic/beats/pull/9483)fields.ecs.yml
(https://github.com/elastic/beats/issues/9318)auditbeat
andx-pack/auditbeat
(done: https://github.com/elastic/beats/pull/9362)feature-auditbeat-host
(done: https://github.com/elastic/beats/pull/9546)1. Host
2. Process
process
, implement scheduled state reporting, and change to single documents (merged: https://github.com/elastic/beats/pull/9139)3. Socket
4. User
/etc/shadow
opt-in, and do multiple rounds of SHA-512 hashing (done: https://github.com/elastic/beats/pull/9461)Main PRs (no longer maintained)
https://github.com/elastic/beats/pull/8356 (MERGED - Rename sysinfo module to system) https://github.com/elastic/beats/pull/8436 (MERGED - Add host, packages, and processes metricsets) https://github.com/elastic/beats/pull/8835 (MERGED - Add user metricset) https://github.com/elastic/beats/pull/8834 (MERGED - Socket metricset) https://github.com/elastic/beats/pull/9139 (MERGED - Update process metricset) https://github.com/elastic/beats/pull/9362 (MERGED - Add CI testing) https://github.com/elastic/beats/pull/9421 (MERGED - Update host metricset) https://github.com/elastic/beats/pull/9461 (MERGED - Opt-in to detecting password changes) https://github.com/elastic/beats/pull/9483 (MERGED - Add message field) https://github.com/elastic/beats/pull/9512 (MERGED - System module documentation) https://github.com/elastic/beats/pull/9546 (MERGED - Add system module)