DOCS Audit event attributes in new format#35510
DOCS Audit event attributes in new format#35510albertzaharovits merged 11 commits intoelastic:masterfrom
Conversation
|
Pinging @elastic/es-security |
|
|
||
| The following list shows attributes that are common to all audit events. | ||
| Their names and values are analogous to those in the deprecated `logfile` or | ||
| `index` output formats. However, it is expected that the formats will evolve |
There was a problem hiding this comment.
Is it correct that the index output format is deprecated? If not, maybe change this phrase to "... the index or deprecated logfile output format..."
There was a problem hiding this comment.
I intended to keep it vague.
It is not technically deprecated yet. But I very much expect it to be in 6.x . We first need to have the filebeat parse the new logfile format . After that, deprecate it and write a blog post.
Is it really ambiguous as I intended it to be? If it implies that it is deprecated now, then it is wrong and I should correct it.
lcawl
left a comment
There was a problem hiding this comment.
I have one question, otherwise LGTM. I verified that it builds successfully.
|
Thank you @lcawl ! |
|
run gradle build tests |
1 similar comment
|
run gradle build tests |
|
run gradle build tests 1 |
Accounts for the `Structured Audit Entries` in the format documentation.
Accounts for the `Structured Audit Entries` in the format documentation.
* master: DOCS Audit event attributes in new format (elastic#35510) Scripting: Actually add joda time back to whitelist (elastic#35965) [DOCS] fix HLRC ILM doc misreferenced tag Add realm information for Authenticate API (elastic#35648) [ILM] add HLRC docs to remove-policy-from-index (elastic#35759) [Rollup] Update serialization version after backport [Rollup] Add more diagnostic stats to job (elastic#35471) Build: Fix gradle build for Mac OS (elastic#35968) Adds deprecation logging to ScriptDocValues#getValues. (elastic#34279) [Monitoring] Make Exporters Async (elastic#35765) [ILM] reduce time restriction on IndexLifecycleExplainResponse (elastic#35954) Remove use of AbstractComponent in xpack (elastic#35394) Deprecate types in search and multi search templates. (elastic#35669) Remove fromXContent from IndexUpgradeInfoResponse (elastic#35934)
This is the spring cleaning in the audit event attributes docs.
A lot has changed and the docs have been left behind.
Some of the documented updates: