New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Session view processor procfs #38799
Commits on Jan 10, 2024
-
Add a add_session_metadata auditbeat processor
This processor will enrich process events with additional infomation needed to enable session view in Kibana. This processor can be run on Linux systems, and will use eBPF to enrich auditd events for process exec and exit events. The additional fields that will be added are information on process parent, session leader and process group leader.
Configuration menu - View commit details
-
Copy full SHA for 88d0a0e - Browse repository at this point
Copy the full SHA 88d0a0eView commit details
Commits on Jan 12, 2024
-
Configuration menu - View commit details
-
Copy full SHA for d5a01bf - Browse repository at this point
Copy the full SHA d5a01bfView commit details
Commits on Jan 15, 2024
-
Calculate process entry leader
Calculate and append entry leader information to enriched processes.
Configuration menu - View commit details
-
Copy full SHA for 7cec455 - Browse repository at this point
Copy the full SHA 7cec455View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7de480d - Browse repository at this point
Copy the full SHA 7de480dView commit details
Commits on Jan 16, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 782504c - Browse repository at this point
Copy the full SHA 782504cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 6b7037b - Browse repository at this point
Copy the full SHA 6b7037bView commit details
Commits on Jan 17, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 0f610cb - Browse repository at this point
Copy the full SHA 0f610cbView commit details -
Apply suggestions from code review
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c688f5a - Browse repository at this point
Copy the full SHA c688f5aView commit details -
Configuration menu - View commit details
-
Copy full SHA for f35b4c7 - Browse repository at this point
Copy the full SHA f35b4c7View commit details
Commits on Jan 18, 2024
-
Remove the DB interface, as there will only be one implementation for it
Configuration menu - View commit details
-
Copy full SHA for bf38e89 - Browse repository at this point
Copy the full SHA bf38e89View commit details -
Configuration menu - View commit details
-
Copy full SHA for 910aba2 - Browse repository at this point
Copy the full SHA 910aba2View commit details -
Configuration menu - View commit details
-
Copy full SHA for 0cbb970 - Browse repository at this point
Copy the full SHA 0cbb970View commit details -
Configuration menu - View commit details
-
Copy full SHA for 06b7064 - Browse repository at this point
Copy the full SHA 06b7064View commit details -
Configuration menu - View commit details
-
Copy full SHA for be57ad8 - Browse repository at this point
Copy the full SHA be57ad8View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9ad7811 - Browse repository at this point
Copy the full SHA 9ad7811View commit details -
Configuration menu - View commit details
-
Copy full SHA for f6aad7e - Browse repository at this point
Copy the full SHA f6aad7eView commit details
Commits on Jan 21, 2024
-
Add Procfs provider for add_session_view processor
Add a procfs provider to the add_session_view processor, which can be used to gather session metadata on systems where the ebpf implementation is not supported.
Configuration menu - View commit details
-
Copy full SHA for 3f0bdae - Browse repository at this point
Copy the full SHA 3f0bdaeView commit details
Commits on Jan 22, 2024
-
* Changed to use time.Duration in timeutils for process start NS * Used go-cmp library to compare ECS docs in tests
Configuration menu - View commit details
-
Copy full SHA for 3598b3c - Browse repository at this point
Copy the full SHA 3598b3cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 743e8da - Browse repository at this point
Copy the full SHA 743e8daView commit details -
Configuration menu - View commit details
-
Copy full SHA for 17fdf1c - Browse repository at this point
Copy the full SHA 17fdf1cView commit details
Commits on Jan 23, 2024
-
Fix linter warnings and upgrade go-libaudit to v2.5.0
Configuration menu - View commit details
-
Copy full SHA for 1ab4752 - Browse repository at this point
Copy the full SHA 1ab4752View commit details -
Configuration menu - View commit details
-
Copy full SHA for 23e097c - Browse repository at this point
Copy the full SHA 23e097cView commit details
Commits on Jan 24, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 882f8a4 - Browse repository at this point
Copy the full SHA 882f8a4View commit details -
Use single channel from epbevents
ebpfevents library has been updated to use a single channel. Updated to use latest ebpfevents library and the single channel.
Configuration menu - View commit details
-
Copy full SHA for 145f627 - Browse repository at this point
Copy the full SHA 145f627View commit details
Commits on Jan 25, 2024
-
Use watcher, which provides singleton access for ebpfevents
Configuration menu - View commit details
-
Copy full SHA for e9aea4d - Browse repository at this point
Copy the full SHA e9aea4dView commit details
Commits on Jan 26, 2024
-
Configuration menu - View commit details
-
Copy full SHA for c001219 - Browse repository at this point
Copy the full SHA c001219View commit details -
Update x-pack/auditbeat/internal/ebpf/watcher_linux.go
Co-authored-by: Mattia Meleleo <melmat@tuta.io>
Configuration menu - View commit details
-
Copy full SHA for a5986dd - Browse repository at this point
Copy the full SHA a5986ddView commit details
Commits on Jan 27, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 5658c76 - Browse repository at this point
Copy the full SHA 5658c76View commit details
Commits on Jan 29, 2024
-
Configuration menu - View commit details
-
Copy full SHA for d5da140 - Browse repository at this point
Copy the full SHA d5da140View commit details -
Merge branch 'session_view_processor_ebpf' of github.com:mjwolf/beats…
… into session_view_processor_ebpf
Configuration menu - View commit details
-
Copy full SHA for ca81839 - Browse repository at this point
Copy the full SHA ca81839View commit details -
Merge remote-tracking branch 'origin/session_view_processor_ebpf' int…
…o session_view_processor_procfs
Configuration menu - View commit details
-
Copy full SHA for b1ee150 - Browse repository at this point
Copy the full SHA b1ee150View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7fe0ba4 - Browse repository at this point
Copy the full SHA 7fe0ba4View commit details -
Configuration menu - View commit details
-
Copy full SHA for 793b473 - Browse repository at this point
Copy the full SHA 793b473View commit details
Commits on Jan 30, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 9c59a7b - Browse repository at this point
Copy the full SHA 9c59a7bView commit details -
Merge remote-tracking branch 'origin/session_view_processor_ebpf' int…
…o session_view_processor_procfs
Configuration menu - View commit details
-
Copy full SHA for fc5a8e6 - Browse repository at this point
Copy the full SHA fc5a8e6View commit details
Commits on Jan 31, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 02cb329 - Browse repository at this point
Copy the full SHA 02cb329View commit details
Commits on Feb 1, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 26d759b - Browse repository at this point
Copy the full SHA 26d759bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 4a304df - Browse repository at this point
Copy the full SHA 4a304dfView commit details
Commits on Feb 2, 2024
-
Configuration menu - View commit details
-
Copy full SHA for e7a45ea - Browse repository at this point
Copy the full SHA e7a45eaView commit details -
Configuration menu - View commit details
-
Copy full SHA for 5dbe5dd - Browse repository at this point
Copy the full SHA 5dbe5ddView commit details -
Configuration menu - View commit details
-
Copy full SHA for 06e2c13 - Browse repository at this point
Copy the full SHA 06e2c13View commit details
Commits on Feb 5, 2024
-
Configuration menu - View commit details
-
Copy full SHA for d675c53 - Browse repository at this point
Copy the full SHA d675c53View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1837289 - Browse repository at this point
Copy the full SHA 1837289View commit details -
Merge remote-tracking branch 'origin/session_view_processor_ebpf' int…
…o session_view_processor_procfs
Configuration menu - View commit details
-
Copy full SHA for b09ca36 - Browse repository at this point
Copy the full SHA b09ca36View commit details
Commits on Feb 6, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 7017a79 - Browse repository at this point
Copy the full SHA 7017a79View commit details
Commits on Feb 7, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 10e9525 - Browse repository at this point
Copy the full SHA 10e9525View commit details -
Configuration menu - View commit details
-
Copy full SHA for eeab397 - Browse repository at this point
Copy the full SHA eeab397View commit details
Commits on Feb 20, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 7de070e - Browse repository at this point
Copy the full SHA 7de070eView commit details -
Configuration menu - View commit details
-
Copy full SHA for 565eaa1 - Browse repository at this point
Copy the full SHA 565eaa1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 12643f4 - Browse repository at this point
Copy the full SHA 12643f4View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1f05b14 - Browse repository at this point
Copy the full SHA 1f05b14View commit details -
Configuration menu - View commit details
-
Copy full SHA for 0ecb7bf - Browse repository at this point
Copy the full SHA 0ecb7bfView commit details -
Merge branch 'session_view_processor_ebpf' of github.com:mjwolf/beats…
… into session_view_processor_ebpf
Configuration menu - View commit details
-
Copy full SHA for fe4f0a3 - Browse repository at this point
Copy the full SHA fe4f0a3View commit details
Commits on Feb 22, 2024
-
Configuration menu - View commit details
-
Copy full SHA for f2443cd - Browse repository at this point
Copy the full SHA f2443cdView commit details
Commits on Mar 11, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 9a52b90 - Browse repository at this point
Copy the full SHA 9a52b90View commit details
Commits on Mar 14, 2024
-
Remove possibilities of panics
Remove possibe panics in program initialization, and handle unexpected events more gracefully.
Configuration menu - View commit details
-
Copy full SHA for 36c8998 - Browse repository at this point
Copy the full SHA 36c8998View commit details -
Configuration menu - View commit details
-
Copy full SHA for 5f5f777 - Browse repository at this point
Copy the full SHA 5f5f777View commit details -
Merge remote-tracking branch 'origin/session_view_processor_ebpf' int…
…o session_view_processor_procfs
Configuration menu - View commit details
-
Copy full SHA for b43e9bc - Browse repository at this point
Copy the full SHA b43e9bcView commit details
Commits on Mar 18, 2024
-
Configuration menu - View commit details
-
Copy full SHA for afe10b2 - Browse repository at this point
Copy the full SHA afe10b2View commit details
Commits on Mar 19, 2024
-
Retry scraping process if ancestry incomplete
If any process ancestry is incomplete, retry scraping the info from proc. As procfs scraping can miss events, or not be updated when process re-parenting happens, if any inconsistancy in the DB is found, rescrape to update the data.
Configuration menu - View commit details
-
Copy full SHA for 82572d2 - Browse repository at this point
Copy the full SHA 82572d2View commit details
Commits on Apr 10, 2024
-
Configuration menu - View commit details
-
Copy full SHA for f2a538f - Browse repository at this point
Copy the full SHA f2a538fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 67004c4 - Browse repository at this point
Copy the full SHA 67004c4View commit details
Commits on Apr 12, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 9229f97 - Browse repository at this point
Copy the full SHA 9229f97View commit details
Commits on Apr 15, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 16be56e - Browse repository at this point
Copy the full SHA 16be56eView commit details -
Configuration menu - View commit details
-
Copy full SHA for 4603027 - Browse repository at this point
Copy the full SHA 4603027View commit details -
Configuration menu - View commit details
-
Copy full SHA for db82ab7 - Browse repository at this point
Copy the full SHA db82ab7View commit details