-
Notifications
You must be signed in to change notification settings - Fork 25k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
DOCS Audit event attributes in new format #35510
DOCS Audit event attributes in new format #35510
Conversation
Pinging @elastic/es-security |
|
||
The following list shows attributes that are common to all audit events. | ||
Their names and values are analogous to those in the deprecated `logfile` or | ||
`index` output formats. However, it is expected that the formats will evolve |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is it correct that the index
output format is deprecated? If not, maybe change this phrase to "... the index or deprecated logfile output format..."
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I intended to keep it vague.
It is not technically deprecated yet. But I very much expect it to be in 6.x . We first need to have the filebeat parse the new logfile format . After that, deprecate it and write a blog post.
Is it really ambiguous as I intended it to be? If it implies that it is deprecated now, then it is wrong and I should correct it.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have one question, otherwise LGTM. I verified that it builds successfully.
Thank you @lcawl ! |
run gradle build tests |
1 similar comment
run gradle build tests |
run gradle build tests 1 |
Accounts for the `Structured Audit Entries` in the format documentation.
Accounts for the `Structured Audit Entries` in the format documentation.
* master: DOCS Audit event attributes in new format (elastic#35510) Scripting: Actually add joda time back to whitelist (elastic#35965) [DOCS] fix HLRC ILM doc misreferenced tag Add realm information for Authenticate API (elastic#35648) [ILM] add HLRC docs to remove-policy-from-index (elastic#35759) [Rollup] Update serialization version after backport [Rollup] Add more diagnostic stats to job (elastic#35471) Build: Fix gradle build for Mac OS (elastic#35968) Adds deprecation logging to ScriptDocValues#getValues. (elastic#34279) [Monitoring] Make Exporters Async (elastic#35765) [ILM] reduce time restriction on IndexLifecycleExplainResponse (elastic#35954) Remove use of AbstractComponent in xpack (elastic#35394) Deprecate types in search and multi search templates. (elastic#35669) Remove fromXContent from IndexUpgradeInfoResponse (elastic#35934)
This is the spring cleaning in the audit event attributes docs.
A lot has changed and the docs have been left behind.
Some of the documented updates: