New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix RFC5424 syslog parser to return Z as a timestamp offset #35360
Conversation
This pull request does not have a backport label.
To fixup this pull request, you need to add the backport labels for the needed
|
daa9190
to
42d2544
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks. LGTM after minor nit.
/test |
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
This pull request is now in conflicts. Could you fix it? 🙏
|
/test |
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
/test |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks
(cherry picked from commit ef1e666)
What does this PR do?
Fixes an operator precedence issue in Filebeat's RFC5424 syslog parser. Timestamps with an offset of 'Z' were being accepted but the 'Z' was being ignored so the default timezone was used, rather than UTC.
Why is it important?
If an RFC5424 syslog entry is received with a time offset of 'Z' and the default timezone is not UTC, the timestamp will be incorrect.
Checklist
I have commented my code, particularly in hard-to-understand areasI have made corresponding changes to the documentationI have made corresponding change to the default configuration filesCHANGELOG.next.asciidoc
orCHANGELOG-developer.next.asciidoc
.Note: no new tests have been added, but the existing tests have been fixed. They were using a timestamp with a 'Z' offset but not requiring the timezone to be UTC.