New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Deprecate index audit output type #37301
Deprecate index audit output type #37301
Conversation
Pinging @elastic/es-security |
The beats work to handle this deprecation is close to being done: elastic/beats#8852 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry I was too quick with the LGTM. This should also add a check in NodeDeprecationChecks
Ah, right. |
@jaymode I went for a new PR to add the |
This PR deprecates the index audit output.
In general, the problem with it is that event indexing can be slower than the rate with which audit events are generated, especially during the daily rollovers or the rolling cluster upgrades. In this situation audit events will be lost which is a terrible failure case for an audit system.
I will follow-up with the removal PR for 7.0 .
Relates #29881
CC @ycombinator