elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.65k stars 8.23k forks source link

Add Endpoint advanced options for capture mode and session data #127282

Open ferullo opened 2 years ago

ferullo commented 2 years ago

Please add two Linux-only advanced options to Endpoint's policy for 8.2. Both are new to 8.2. Adding these entries now will enable end-to-end testing in 8.2.0-SNAPSHOT builds.

inputs[0].policy.linux.advanced.kernel.capture_mode Allowed values are auto, kprobe, or ebpf. The default is kprobe currently but we intend for it to change to auto before 8.2 FF.

inputs[0].policy.linux.advanced.events.session_data Allowed values are true and false. The default is currently false but it may change to true before 8.2 FF.

cc @qcorporation @kevinlog @softengchick

elasticmachine commented 2 years ago

Pinging @elastic/security-onboarding-and-lifecycle-mgt (Team:Onboarding and Lifecycle Mgt)

kevinlog commented 2 years ago

I will add this in for 8.2