Repository navigation
[AuditdManager] Reverting Session Data option - #11420
Conversation
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
🚀 Benchmarks reportPackage
|
| Data stream | Previous EPS | New EPS | Diff (%) | Result |
|---|---|---|---|---|
auditd |
13698.63 | 9009.01 | -4689.62 (-34.23%) | 💔 |
To see the full report comment with /test benchmark fullreport
| version: "1.18.1" | ||
| description: "The Auditd Manager Integration receives audit events from the Linux Audit Framework that is a part of the Linux kernel." | ||
| type: integration | ||
| categories: |
There was a problem hiding this comment.
The change to include ^9.0.0 in the kibana condition should be backed out too. As per the email to the elastic-packages mailing list,
"TLDR; Please don't update the kibana constraints in packages for 9.0.0 yet. We will communicate a more definitive plan in the following weeks."
There was a problem hiding this comment.
Reverted, thanks for the info
| failure_mode: {{failure_mode}} | ||
| {{#if session_data}} | ||
| audit_rules: "{{escape_multiline_string audit_rules}} | ||
| {{escape_multiline_string " |
There was a problem hiding this comment.
Regarding escape_multiline_string, if we could get a to_json function (that doesn't exempt string types) this would cover many use cases of properly encoding data for use inside of YAML. The fact that the current to_json helper exempts strings makes is almost useless (in fact, it's never used in this repo). I would love to see the string exemption removed, then we could use to_json here to form a properly escaped string.
For example, this would become audit_rules: {{ to_json audit_rules }}, and we would not have to think about escaping anything because JSON encoding is entirely valid within YAML.
There was a problem hiding this comment.
yes, it is similar to what I faced when I noticed that escape_string always wraps the string with single quotes, it doesn't allow for flexibility with concatenating YAMLs.
I will check the possibility of enhancing the to_json in Kibana to remove the string exempt instead if that can provide more value, I didn't notice it wasn't being used
|
💚 Build Succeeded
History
|
|
Package auditd_manager - 1.18.1 containing this change is available at https://epr.elastic.co/search?package=auditd_manager |
* reverting session_data toggle * updating PR changelog * fixing change type * reverting kibana changes
* reverting session_data toggle * updating PR changelog * fixing change type * reverting kibana changes




Proposed commit message
This PR reverts the Session Data option introduced on this PR.
The revert is needed because the
1.8.0version relies on theescape_multiline_stringhelper that was introduced in Kibana in this PR.It fixes the error below when attempting to save the Auditd Manager integration version
1.8.0in Serverless environments that don't contain the Kibana changes:Reasoning:
1.8.0 manifest was set to be enabled Starting on Kibana 8.16+, but serverless release cadences follow a different cadence and it's on version 9.0.0 already, therefore this Kibana PR must be deployed on serverless in order to
escape_multiline_stringbe available.Checklist
changelog.ymlfile.