You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Here is a sample event is export format that contains _CAP_EFFECTIVE: journald.export.txt
Describe a specific use case for the enhancement or feature:
Our software should be aligned to ECS where possible. Formatting the data in the same way makes is possible to uniformly query all processes data that mentions a given Linux capability.
Describe the enhancement:
journald has a
_CAP_EFFECTIVE
field 1. This could be used to populate the ECS 8.10 process.thread.capabilities.effective field from the journald input code.Here is a sample event is export format that contains
_CAP_EFFECTIVE
: journald.export.txtDescribe a specific use case for the enhancement or feature:
Our software should be aligned to ECS where possible. Formatting the data in the same way makes is possible to uniformly query all processes data that mentions a given Linux capability.
Footnotes
https://www.freedesktop.org/software/systemd/man/systemd.journal-fields.html#Trusted%20Journal%20Fields ↩
The text was updated successfully, but these errors were encountered: