Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add systemd service status to SIEM host page #50115

Open
philippkahr opened this issue Nov 10, 2019 · 3 comments
Open

Add systemd service status to SIEM host page #50115

philippkahr opened this issue Nov 10, 2019 · 3 comments
Labels
enhancement New value added to drive a business result Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@philippkahr
Copy link
Contributor

Describe the feature:

@fearful-symmetry released a systemd integration to find out if services are stopped, dead, running. elastic/beats#14206 I think it would be nice if those show up in the SIEM app as an extra tab. Maybe it is possible to correlate the uncommon processes to the systemd services? E.g. is a process was spawned from systemd?

Screenshot 2019-11-10 at 11 44 36

@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@willemdh
Copy link

Same for Windows services pls

@philippkahr
Copy link
Contributor Author

@willemdh true! Windows services are already collected with metricbeat and the windows module.

@tsg tsg added the enhancement New value added to drive a business result label Nov 11, 2019
@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

6 participants