-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Auditbeat] Cherry-pick #9963 to 6.x: Add user information to processes #10395
Conversation
Adds real, effective, and saved UID and GID information to the process dataset. (cherry picked from commit fa40a54)
Pinging @elastic/secops |
I've had to add |
jenkins, test this |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
jenkins, test this |
Cherry-pick of PR #9963 to 6.x branch. Original message:
Since
go-sysinfo
can now report the UIDs and GIDs of a process, this adds this information to theprocess
metricset.The added fields are:
user.id
(UID or SID)user.name
user.group.id
(GID or SID of primary group)user.group.name
user.effective.id
(EUID)user.effective.group.id
(EGID)user.saved.id
(SUID)user.saved.group.id
(SGID)Also adds some unit tests and tightens the system test.