Skip to content

[Auditd_Manager] fixing wrong field type for auditd.data.exit #6111

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
May 9, 2023

Conversation

P1llus
Copy link
Member

@P1llus P1llus commented May 5, 2023

What does this PR do?

Fixes wrong field type for auditd.data.exit. It was keyword in auditbeat and seems to convert to a keyword/string value if the integer value is known, or the exit code is a string by itself.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Related issues

@P1llus P1llus added bug Something isn't working, use only for issues Team:Security-External Integrations Integration:auditd_manager Auditd Manager labels May 5, 2023
@P1llus P1llus requested a review from a team as a code owner May 5, 2023 19:22
@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

Copy link
Contributor

@taylor-swanson taylor-swanson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@elasticmachine
Copy link

elasticmachine commented May 5, 2023

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-05-09T14:11:58.195+0000

  • Duration: 18 min 16 sec

Test stats 🧪

Test Results
Failed 0
Passed 21
Skipped 0
Total 21

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine
Copy link

elasticmachine commented May 5, 2023

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (1/1) 💚
Files 100.0% (1/1) 💚 50.0
Classes 100.0% (1/1) 💚 50.0
Methods 88.889% (8/9) 👍 19.658
Lines 90.206% (175/194) 👍 19.836
Conditionals 100.0% (0/0) 💚

Copy link
Contributor

@efd6 efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs a test expectation update.

@BenB196
Copy link
Contributor

BenB196 commented May 8, 2023

(FYI) This looks like it will resolve #4860

Copy link
Member

@andrewkroh andrewkroh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The exit code is always a string in the JSON from auditbeat. go-libaudit translates numbers to named POSIX exit codes if possible.

@P1llus P1llus merged commit d49cc05 into elastic:main May 9, 2023
@elasticmachine
Copy link

Package auditd_manager - 1.7.1 containing this change is available at https://epr.elastic.co/search?package=auditd_manager

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working, use only for issues Integration:auditd_manager Auditd Manager
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[auditd_manager] Integration can throw illegal_argument_exception
6 participants