New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rename process.exe to process.executable for ECS #9949
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@andrewkroh It seems there is also in auditbeat process.exe
?
Yes, the Auditbeat auditd module produces this field. beats/auditbeat/module/auditd/audit_linux.go Line 571 in ae290b4
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
I added to this PR the change in the auditd module in auditbeat. |
@andrewkroh Could you take another look as it now also affects auditbeat? |
@@ -568,7 +568,7 @@ func addProcess(p aucoalesce.Process, m common.MapStr) { | |||
process["name"] = p.Name | |||
} | |||
if p.Exe != "" { | |||
process["exe"] = p.Exe | |||
process["executable"] = p.Exe |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This package has a data.json and I think an execve.json that should be updated. You can run go test . -data
on Linux to update them.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done, it unfortunately also removed some entries which are probably available in other envs.
2d655e9
to
941a91f
Compare
This also updates the auditbeat auditd module to use process.executable instead of process.exe.
This also updates the auditbeat auditd module to use process.executable instead of process.exe.