Open jvalente-salemstate opened 3 months ago
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)
Package network_traffic - 1.31.0 containing this change is available at https://epr.elastic.co/search?package=network_traffic
Description
Packetbeat's Documentation includes configuration options that are not included in the integration (at least with managed agents).
packetbeat.interfaces.with_vlans
Aside from fixing that issue,this would also enrich the event with extra information. These fields are included in the exported fields list, but they're not in any of the generated sample events.
packetbeat.ignore_outgoing
Allow users to toggle whether outgoing packets are included. This would support scenarios where only inbound traffic is wanted, or avoiding duplicate captures if both source and destination are running packet capture
Proposed Enhancement
Include toggles in the package manifest for
Network Packet Capture
to enable/disable thewith_vlans
andignore_outgoing
configuration options.