Skip to content

Commit

Permalink
Move user.audit.* and user.filesystem.* to fields.common.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
Christoph Wurm committed Feb 4, 2019
1 parent cfb597a commit 290247d
Show file tree
Hide file tree
Showing 5 changed files with 106 additions and 106 deletions.
32 changes: 32 additions & 0 deletions auditbeat/_meta/fields.common.yml
Expand Up @@ -55,6 +55,17 @@
description: User information.
fields:

- name: audit
type: group
description: Audit user information.
fields:
- name: id
type: keyword
description: Audit user ID.
- name: name
type: keyword
description: Audit user name.

- name: effective
type: group
description: Effective user information.
Expand All @@ -76,6 +87,27 @@
type: keyword
description: Effective group name.

- name: filesystem
type: group
description: Filesystem user information.
fields:
- name: id
type: keyword
description: Filesystem user ID.
- name: name
type: keyword
description: Filesystem user name.
- name: group
type: group
description: Filesystem group information.
fields:
- name: id
type: keyword
description: Filesystem group ID.
- name: name
type: keyword
description: Filesystem group name.

- name: saved
type: group
description: Saved user information.
Expand Down
144 changes: 72 additions & 72 deletions auditbeat/docs/fields.asciidoc
Expand Up @@ -32,78 +32,6 @@ These are the fields generated by the auditd module.
[float]
== audit fields
Audit user information.
*`user.audit.id`*::
+
--
type: keyword
Audit user ID.
--
*`user.audit.name`*::
+
--
type: keyword
Audit user name.
--
[float]
== filesystem fields
Filesystem user information.
*`user.filesystem.id`*::
+
--
type: keyword
Filesystem user ID.
--
*`user.filesystem.name`*::
+
--
type: keyword
Filesystem user name.
--
[float]
== group fields
Filesystem group information.
*`user.filesystem.group.id`*::
+
--
type: keyword
Filesystem group ID.
--
*`user.filesystem.group.name`*::
+
--
type: keyword
Filesystem group name.
--
*`user.auid`*::
+
--
Expand Down Expand Up @@ -2749,6 +2677,30 @@ The object's SELinux level.
User information.
[float]
== audit fields
Audit user information.
*`user.audit.id`*::
+
--
type: keyword
Audit user ID.
--
*`user.audit.name`*::
+
--
type: keyword
Audit user name.
--
[float]
== effective fields
Expand Down Expand Up @@ -2797,6 +2749,54 @@ Effective group name.
--
[float]
== filesystem fields
Filesystem user information.
*`user.filesystem.id`*::
+
--
type: keyword
Filesystem user ID.
--
*`user.filesystem.name`*::
+
--
type: keyword
Filesystem user name.
--
[float]
== group fields
Filesystem group information.
*`user.filesystem.group.id`*::
+
--
type: keyword
Filesystem group ID.
--
*`user.filesystem.group.name`*::
+
--
type: keyword
Filesystem group name.
--
[float]
== saved fields
Expand Down

0 comments on commit 290247d

Please sign in to comment.