Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automatic merge from master to 7.x branch #12224

Merged
merged 60 commits into from
May 22, 2019
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
60 commits
Select commit Hold shift + click to select a range
82e7eec
Use time.Duration directly in GetStartTimeEndTime function (#12033)
kaiyan-sheng May 7, 2019
9653105
Fix memory leak in Filebeat pipeline acker (#12063)
exekias May 7, 2019
354cd4d
Add convert processor (#11686)
andrewkroh May 7, 2019
1fb3d63
Update docs.asciidoc (#11852) (#12045)
dedemorton May 7, 2019
cea4efa
Remove systemd v233 requirement because it's no longer true (#12076)
dedemorton May 7, 2019
cc73643
Don't generate autodiscover config when no port matches host hints (#…
jsoriano May 8, 2019
2a8ee65
Fix transptest testing (#12091)
May 8, 2019
82edc23
Refactor and add tests for template and ilm handling. (#12065)
simitt May 8, 2019
683f4f7
[Auditbeat] Login: Fix re-read of utmp files (#12028)
May 8, 2019
622377a
[Metricbeat][postgresql] Update lib/pq to fix #11393 (#12094)
adriansr May 8, 2019
c17586a
Make breaking changes separate files (#12002)
dedemorton May 8, 2019
043e60d
Change image references to use block syntax not inline (#11911)
dedemorton May 9, 2019
b39edc5
Revert "Make breaking changes separate files (#12002)" (#12116)
dedemorton May 9, 2019
85757fd
fix queue.spool.write.flush.events config type (#12080)
graphaelli May 9, 2019
5cf48bf
Revert printing template and policy name on export. (#12067)
simitt May 9, 2019
ccbf05a
[Filebeat] Add -expected files by default (#12041)
ruflin May 9, 2019
d4f3944
Update vendored gosigar to 0.10.2 (#12101)
adriansr May 9, 2019
a5b3f0a
Fix various memory leaks under Windows (#12100)
adriansr May 9, 2019
89f93e3
New processor extract_array (#11761)
adriansr May 9, 2019
e098e00
[Heartbeat] Remove not needed flags from setup command (#11856)
ruflin May 9, 2019
cc05f62
Skip Windows testing if magefile.go does not exist (#12099)
andrewkroh May 9, 2019
f2473d2
Fix goroutine leak on initialization failures of log input (#12125)
jsoriano May 9, 2019
2cbdc9a
Document and improve permission checks when running socket metricset …
jsoriano May 9, 2019
bbf4156
[metricbeat] added CPU usage check to docker memory stats (#12062)
fearful-symmetry May 9, 2019
1b2613e
Change type from scaled_float to long and add format (#11982)
kaiyan-sheng May 9, 2019
88a2604
[libbeat] Add unit tests for libbeat's client proxy settings (#12044)
faec May 9, 2019
cd5c3ad
[Metricbeat](Etcd-Leader)Followers wont report leader metrics (#12004)
odacremolbap May 9, 2019
44a87a8
Add package libbeat/common/cleanup (#12134)
May 9, 2019
0460448
[docs] add make fmt to contributing guide (#12118)
fearful-symmetry May 9, 2019
6f8ddd6
Move one changelog entry from breaking change to bug fix (#12146)
kaiyan-sheng May 9, 2019
cf5de0a
Sysmon and Security "modules" for Winlogbeat (#11651)
andrewkroh May 9, 2019
c9ffceb
[Auditbeat] Process: Add hash of executable (#11722)
May 9, 2019
8bbbab0
[Docs] Comment out section that contains bad link (#12152)
dedemorton May 9, 2019
65d652d
[Filebeat] Introduce UTC as default timezone for modules tests (#12120)
ruflin May 10, 2019
e4a427d
Add number of goroutines to reported metrics (#12135)
jsoriano May 10, 2019
9ece0af
Add minimal ES template functionality. (#12103)
simitt May 10, 2019
056d921
Refactor logging in pgsql module (#12151)
andrewkroh May 10, 2019
59378cd
Ignore doc type in ES search API for ES 8 (#12171)
jsoriano May 10, 2019
ed55279
[Docs] Make breaking changes separate files for each version (#12173)
dedemorton May 10, 2019
f69dadb
[Filebeat] module for palo_alto (pan-os) logs (#11999)
adriansr May 11, 2019
d5b6a2b
[cmd setup] Add and deprecate setup cmds for index handling (#12132)
simitt May 11, 2019
6f87f3c
Zdd zfs beat (#12136)
maireanu May 13, 2019
d9668d3
[metricbeat] Expand metricbeat dev guide for testing (#12105)
fearful-symmetry May 13, 2019
3003cfb
Bugfix set template.order to 1 by default. (#12160)
simitt May 14, 2019
a1a7d7e
[Auditbeat] Fix issues with multiple calls to rpmReadConfigFiles (#12…
adriansr May 15, 2019
3b0e1c7
[Filebeat] Palo_alto module improvements (#12182)
adriansr May 15, 2019
56764fc
Add mesosbeat to the community beats (#12185)
berfinsari May 16, 2019
f549cec
Missing module.yml.disabled file for palo_alto (#12191)
adriansr May 16, 2019
b5c92a7
[Filebeat] Add RabbitMQ module (#12032)
May 16, 2019
88660dc
[metricbeat] Add linux sockstat data to socket_summary metricset (#12…
fearful-symmetry May 17, 2019
6914806
Fix goroutine leak on non-explicit finalization of log inputs (#12164)
jsoriano May 20, 2019
0495f6c
[Metricbeat] CoreDNS module: Add Kibana Dashboard (#11619)
ioandr May 20, 2019
9c848a9
[Libbeat][Metricbeat]Add IgnoreAllErrors to schema.Conv object (#12089)
May 20, 2019
313e6d1
Add `container` input, deprecate `docker` in favor of it (#12162)
May 20, 2019
d3ef979
[Auditbeat] Fix formatting of config files on macOS and Windows (#12148)
May 20, 2019
eca4b19
[libbeat] Escape BOM on JsonReader before trying to decode line (#11661)
michalpristas May 21, 2019
da783fe
Set beat ID in registries after loading meta file (#12180)
ycombinator May 21, 2019
2ce9c8e
[Filebeat] Move dashboards from 8 to 7 directory (#12217)
ruflin May 21, 2019
c4bc667
Merge branch 'master' into automatic_merge_from_master_to_7.x_branch
ph May 21, 2019
2c9a5aa
adjust doc
ph May 21, 2019
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
6 changes: 5 additions & 1 deletion CHANGELOG-developer.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -35,5 +35,9 @@ The list below covers the major changes between 7.0.0-rc2 and master only.
by `make` and `mage`. Example: `export PYTHON_EXE=python2.7`. {pull}11212[11212]
- Prometheus helper for metricbeat contains now `Namespace` field for `prometheus.MetricsMappings` {pull}11424[11424]
- Update Jinja2 version to 2.10.1. {pull}11817[11817]
- Reduce idxmgmt.Supporter interface and rework export commands to reuse logic. {pull}11777[11777]
- Reduce idxmgmt.Supporter interface and rework export commands to reuse logic. {pull}11777[11777],{pull}12065[12065],{pull}12067[12067],{pull}12160[12160]
- Update urllib3 version to 1.24.2 {pull}11930[11930]
- Add libbeat/common/cleanup package. {pull}12134[12134]
- Only Load minimal template if no fields are provided. {pull}12103[12103]
- Add new option `IgnoreAllErrors` to `libbeat.common.schema` for skipping fields that failed while converting. {pull}12089[12089]
- Deprecate setup cmds for `template` and `ilm-policy`. Add new setup cmd for `index-management`. {pull}12132[12132]
30 changes: 30 additions & 0 deletions CHANGELOG.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Socket dataset: Exclude localhost by default {pull}11993[11993]

*Filebeat*

- Modify apache/error dataset to follow ECS. {pull}8963[8963]
- Rename many `traefik.access.*` fields to map to ECS. {pull}9005[9005]
- Fix parsing of GC entries in elasticsearch server log. {issue}9513[9513] {pull}9810[9810]
Expand Down Expand Up @@ -63,19 +64,27 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Not hiding error in case of http failure using elastic fetcher {pull}11604[11604]
- Relax validation of the X-Pack license UID value. {issue}11640[11640]
- Fix a parsing error with the X-Pack license check on 32-bit system. {issue}11650[11650]
- Escape BOM on JsonReader before trying to decode line {pull}11661[11661]
- Fix ILM policy always being overwritten. {pull}11671[11671]
- Fix template always being overwritten. {pull}11671[11671]
- Fix matching of string arrays in contains condition. {pull}11691[11691]
- Fix formatting for `event.duration`, "human readable" was not working well for this. {pull}11675[11675]
- Fix initialization of the TCP input logger. {pull}11605[11605]
- Fix flaky service_integration_windows_test test by introducing a confidence factor and enriching the error message with more service details. {issue}8880[8880] and {issue}7977[7977]
- Replace wmi queries with win32 api calls as they were consuming CPU resources {issue}3249[3249] and {issue}11840[11840]
- Fix queue.spool.write.flush.events config type. {pull}12080[12080]
- Fixed a memory leak when using the add_process_metadata processor under Windows. {pull}12100[12100]
- Fixed Beat ID being reported by GET / API. {pull}12180[12180]

*Auditbeat*

- Package dataset: dlopen versioned librpm shared objects. {pull}11565[11565]
- Package dataset: Nullify Librpm's rpmsqEnable. {pull}11628[11628]
- Package dataset: Log error when Homebrew is not installed. {pull}11667[11667]
- Process dataset: Fixed a memory leak under Windows. {pull}12100[12100]
- Login dataset: Fix re-read of utmp files. {pull}12028[12028]
- Package dataset: Fixed a crash inside librpm after Auditbeat has been running for a while. {issue}12147[12147] {pull}12168[12168]
- Fix formatting of config files on macOS and Windows. {pull}12148[12148]

*Filebeat*

Expand All @@ -87,6 +96,9 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Fix `add_docker_metadata` source matching, using `log.file.path` field now. {pull}11577[11577]
- Add missing Kubernetes metadata fields to Filebeat CoreDNS module, and fix a documentation error. {pull}11591[11591]
- Reduce memory usage if long lines are truncated to fit `max_bytes` limit. The line buffer is copied into a smaller buffer now. This allows the runtime to release unused memory earlier. {pull}11524[11524]
- Fix memory leak in Filebeat pipeline acker. {pull}12063[12063]
- Fix goroutine leak caused on initialization failures of log input. {pull}12125[12125]
- Fix goroutine leak on non-explicit finalization of log input. {pull}12164[12164]

*Heartbeat*

Expand All @@ -105,11 +117,19 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Change diskio metrics retrieval method (only for Windows) from wmi query to DeviceIOControl function using the IOCTL_DISK_PERFORMANCE control code {pull}11635[11635]
- Call GetMetricData api per region instead of per instance. {issue}11820[11820] {pull}11882[11882]
- Update documentation with cloudwatch:ListMetrics permission. {pull}11987[11987]
- Check permissions in system socket metricset based on capabilities. {pull}12039[12039]
- Get process information from sockets owned by current user when system socket metricset is run without privileges. {pull}12039[12039]
- Avoid generating hints-based configuration with empty hosts when no exposed port is suitable for the hosts hint. {issue}8264[8264] {pull}12086[12086]
- Fixed a socket leak in the postgresql module under Windows when SSL is disabled on the server. {pull}11393[11393]
- Change some field type from scaled_float to long in aws module. {pull}11982[11982]
- Fixed RabbitMQ `queue` metricset gathering when `consumer_utilisation` is set empty at the metrics source {pull}12089[12089]

*Packetbeat*

- Prevent duplicate packet loss error messages in HTTP events. {pull}10709[10709]
- Avoid reporting unknown MongoDB opcodes more than once. {pull}10878[10878]
- Fixed a memory leak when using process monitoring under Windows. {pull}12100[12100]
- Improved debug logging efficiency in PGQSL module. {issue}12150[12150]

*Winlogbeat*

Expand All @@ -134,12 +154,16 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Updated go-seccomp-bpf library to v1.1.0 which updates syscall lists for Linux v5.0. {pull}NNNN[NNNN]
- Add `add_observer_metadata` processor. {pull}11394[11394]
- Add `decode_csv_fields` processor. {pull}11753[11753]
- Add `convert` processor for converting data types of fields. {issue}8124[8124] {pull}11686[11686]
- New `extract_array` processor. {pull}11761[11761]
- Add number of goroutines to reported metrics. {pull}12135[12135]

*Auditbeat*

- Auditd module: Add `event.outcome` and `event.type` for ECS. {pull}11432[11432]
- Package: Enable suse. {pull}11634[11634]
- Add support to the system package dataset for the SUSE OS family. {pull}11634[11634]
- Process: Add file hash of process executable. {pull}11722[11722]

*Filebeat*

Expand All @@ -157,6 +181,9 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Add Filebeat envoyproxy module. {pull}11700[11700]
- Add apache2(httpd) log path (`/var/log/httpd`) to make apache2 module work out of the box on Redhat-family OSes. {issue}11887[11887] {pull}11888[11888]
- Add support to new MongoDB additional diagnostic information {pull}11952[11952]
- New module `palo_alto` for Palo Alto Networks PAN-OS logs. {pull}11999[11999]
- Add RabbitMQ module. {pull}12032[12032]
- Add new `container` input. {pull}12162[12162]

*Heartbeat*

Expand All @@ -179,6 +206,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Add check on object name in the counter path if the instance name is missing {issue}6528[6528] {pull}11878[11878]
- Add AWS cloudwatch metricset. {pull}11798[11798] {issue}11734[11734]
- Add `regions` in aws module config to specify target regions for querying cloudwatch metrics. {issue}11932[11932] {pull}11956[11956]
- Keep `etcd` followers members from reporting `leader` metricset events {pull}12004[12004]

*Packetbeat*

Expand All @@ -196,6 +224,8 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d

*Filebeat*

- `docker` input is deprecated in favour `container`. {pull}12162[12162]

*Heartbeat*

*Journalbeat*
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks OK to me

Expand Down
10 changes: 5 additions & 5 deletions NOTICE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -715,15 +715,15 @@ Apache License 2.0

--------------------------------------------------------------------
Dependency: github.com/elastic/go-sysinfo
Revision: ab4f04edfc3d6b3864f5f06a068ddab9ad79774f
Revision: 9a4be54a53be4c48b44d351d52fb425a5e274be5
License type (autodetected): Apache-2.0
./vendor/github.com/elastic/go-sysinfo/LICENSE.txt:
--------------------------------------------------------------------
Apache License 2.0

-------NOTICE.txt-----
Elastic go-sysinfo
Copyright 2017-2018 Elasticsearch B.V.
Copyright 2017-2019 Elasticsearch B.V.

This product includes software developed at
Elasticsearch, B.V. (https://www.elastic.co/).
Expand Down Expand Up @@ -765,8 +765,8 @@ Elasticsearch, B.V. (https://www.elastic.co/).

--------------------------------------------------------------------
Dependency: github.com/elastic/gosigar
Version: v0.10.1
Revision: fc57ef8c6efc0b4fdc6d7c623173073a6d3d4736
Version: v0.10.2
Revision: 1227b9d6877d126ad640087e44439d70dba2df4f
License type (autodetected): Apache-2.0
./vendor/github.com/elastic/gosigar/LICENSE:
--------------------------------------------------------------------
Expand Down Expand Up @@ -1921,7 +1921,7 @@ Apache License 2.0

--------------------------------------------------------------------
Dependency: github.com/lib/pq
Revision: 2704adc878c21e1329f46f6e56a1c387d788ff94
Revision: 2ff3cb3adc01768e0a552b3a02575a6df38a9bea
License type (autodetected): MIT
./metricbeat/module/postgresql/vendor/github.com/lib/pq/LICENSE.md:
--------------------------------------------------------------------
Expand Down
151 changes: 151 additions & 0 deletions auditbeat/docs/fields.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -6540,6 +6540,157 @@ type: keyword
ID uniquely identifying the process. It is computed as a SHA-256 hash of the host ID, PID, and process start time.


--

[float]
== hash fields

Hashes of the executable. The keys are algorithm names and the values are the hex encoded digest values.



*`process.hash.blake2b_256`*::
+
--
type: keyword

BLAKE2b-256 hash of the executable.

--

*`process.hash.blake2b_384`*::
+
--
type: keyword

BLAKE2b-384 hash of the executable.

--

*`process.hash.blake2b_512`*::
+
--
type: keyword

BLAKE2b-512 hash of the executable.

--

*`process.hash.md5`*::
+
--
type: keyword

MD5 hash of the executable.

--

*`process.hash.sha1`*::
+
--
type: keyword

SHA1 hash of the executable.

--

*`process.hash.sha224`*::
+
--
type: keyword

SHA224 hash of the executable.

--

*`process.hash.sha256`*::
+
--
type: keyword

SHA256 hash of the executable.

--

*`process.hash.sha384`*::
+
--
type: keyword

SHA384 hash of the executable.

--

*`process.hash.sha3_224`*::
+
--
type: keyword

SHA3_224 hash of the executable.

--

*`process.hash.sha3_256`*::
+
--
type: keyword

SHA3_256 hash of the executable.

--

*`process.hash.sha3_384`*::
+
--
type: keyword

SHA3_384 hash of the executable.

--

*`process.hash.sha3_512`*::
+
--
type: keyword

SHA3_512 hash of the executable.

--

*`process.hash.sha512`*::
+
--
type: keyword

SHA512 hash of the executable.

--

*`process.hash.sha512_224`*::
+
--
type: keyword

SHA512/224 hash of the executable.

--

*`process.hash.sha512_256`*::
+
--
type: keyword

SHA512/256 hash of the executable.

--

*`process.hash.xxh64`*::
+
--
type: keyword

XX64 hash of the executable.

--


Expand Down
2 changes: 1 addition & 1 deletion auditbeat/docs/getting-started.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -282,4 +282,4 @@ The dashboards are provided as examples. We recommend that you
{kibana-ref}/dashboard.html[customize] them to meet your needs.

[role="screenshot"]
image:./images/auditbeat-file-integrity-dashboard.png[Auditbeat File Integrity Dashboard]
image::./images/auditbeat-file-integrity-dashboard.png[Auditbeat File Integrity Dashboard]
1 change: 1 addition & 0 deletions auditbeat/docs/modules/auditd.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -298,5 +298,6 @@ auditbeat.modules:
#-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -k access
#-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -k access


----

Loading