Skip to content

[Osquerybeat] Add support for marshalling embedded structs#47746

Merged
brian-mckinney merged 3 commits intoelastic:mainfrom
brian-mckinney:encoding_embedded_struct
Nov 21, 2025
Merged

[Osquerybeat] Add support for marshalling embedded structs#47746
brian-mckinney merged 3 commits intoelastic:mainfrom
brian-mckinney:encoding_embedded_struct

Conversation

@brian-mckinney
Copy link
Contributor

@brian-mckinney brian-mckinney commented Nov 20, 2025

Proposed commit message

Updates osquery encoding to support marshalling structs with embedded fields. This is going to be needed for jumplists, but can be useful elsewhere as well

Example

type Meta struct {
    ID        string `osquery:"id"`
    CreatedAt time.Time `osquery:"created_at" format:"unix"`
}

type User struct {
    Meta
    Name string `osquery:"name"`
}

user := User{
Meta: Meta{
	ID:        "123",
	CreatedAt: time.Now().UTC(),
    },
    Name: "John Doe",
}
result, _ := MarshalToMapWithFlags(&user, 0)
// result: map[created_at:1763670897 id:123 name:John Doe]

Checklist

  • My code follows the style guidelines of this project
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works. Where relevant, I have used the stresstest.sh script to run them under stress conditions and race detector to verify their stability.
  • I have added an entry in ./changelog/fragments using the changelog tool.

Disruptive User Impact

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Use cases

Screenshots

Logs

@brian-mckinney brian-mckinney self-assigned this Nov 20, 2025
@brian-mckinney brian-mckinney requested a review from a team as a code owner November 20, 2025 20:38
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Nov 20, 2025
@botelastic
Copy link

botelastic bot commented Nov 20, 2025

This pull request doesn't have a Team:<team> label.

@github-actions
Copy link
Contributor

🤖 GitHub comments

Just comment with:

  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)

@mergify
Copy link
Contributor

mergify bot commented Nov 20, 2025

This pull request does not have a backport label.
If this is a bug or security fix, could you label this PR @brian-mckinney? 🙏.
For such, you'll need to label your PR with:

  • The upcoming major version of the Elastic Stack
  • The upcoming minor version of the Elastic Stack (if you're not pushing a breaking change)

To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • backport-8./d is the label to automatically backport to the 8./d branch. /d is the digit
  • backport-active-all is the label that automatically backports to all active branches.
  • backport-active-8 is the label that automatically backports to all active minor branches for the 8 major.
  • backport-active-9 is the label that automatically backports to all active minor branches for the 9 major.

@brian-mckinney brian-mckinney merged commit c1ac13c into elastic:main Nov 21, 2025
29 of 32 checks passed
andrzej-stencel pushed a commit to andrzej-stencel/beats that referenced this pull request Dec 1, 2025
…7746)

* Add support for marshalling embedded structs

* go format

* add changelog fragment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement needs_team Indicates that the issue/PR needs a Team:* label Osquerybeat

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants