-
Notifications
You must be signed in to change notification settings - Fork 4.9k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Auditbeat] New system/socket dataset using kprobes tracing events (#…
…13058) This patch replaces the original `system/socket` dataset which used netlink to periodically poll the system for open sockets. In the new implementation, kprobe-based tracing is used to receive events of interest related to function calls and their arguments inside the kernel tcp/ip stack. From this stream of information the dataset constructs a model of all the network sockets in use and the processes running in the system at any given time. This allows the dataset to produce flow-like events with information like packets and bytes counters, originator process and user, with little impact to system performance and without missing short-lived sockets or processes. The dataset is in beta.
- Loading branch information
Showing
272 changed files
with
88,007 additions
and
11,119 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
3 changes: 0 additions & 3 deletions
3
auditbeat/module/auditd/_meta/audit.rules.d/sample-rules-linux-32bit.conf
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
Oops, something went wrong.