You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The auditd module sets `user.audit.id` and `auditd.session` to `unset`
when they are not present in the original event.
This changes this behavior and removes the fields from the event. The
same logic is applied to any other *ID field that might be marked as
unset.
Closeselastic#11431
The auditd module sets `user.audit.id` and `auditd.session` to `unset`
when they are not present in the original event.
This changes this behavior and removes the fields from the event. The
same logic is applied to any other *ID field that might be marked as
unset.
Closes#11431
It has been requested to drop the user.auid field when the value is
unset
.Likewise we should follow the same practice for the unset session IDs (
auditd.session:unset
).The text was updated successfully, but these errors were encountered: