Skip to content

[Auditd Manager] Add docs to support add_session_metadata processor - #10544

Merged
mjwolf merged 9 commits into
elastic:mainfrom
karenzone:10499-auditd-manager
Aug 21, 2024
Merged

mjwolf merged 9 commits into
elastic:mainfrom
karenzone:10499-auditd-manager

Conversation

@karenzone

Copy link
Copy Markdown
Contributor

Adds documentation for enabling and configuring the add_session_metadata processor for the Auditd Manager integration. The add_session_metadata processor powers the Session View utility in Elastic Security.

Related: elastic/beats#40186
Closes: #10499

@karenzone karenzone added documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request docs labels Jul 19, 2024
@karenzone karenzone self-assigned this Jul 19, 2024
@andrewkroh andrewkroh added Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform] Integration:auditd_manager Auditd Manager labels Jul 19, 2024
Comment thread packages/auditd_manager/_dev/build/docs/README.md Outdated
Comment thread packages/auditd_manager/_dev/build/docs/README.md Outdated
@karenzone
karenzone force-pushed the 10499-auditd-manager branch from 4524a70 to ec5ae34 Compare July 22, 2024 22:11
@karenzone
karenzone force-pushed the 10499-auditd-manager branch from ec5ae34 to 480c5cd Compare July 22, 2024 22:18
@karenzone
karenzone marked this pull request as ready for review July 22, 2024 22:19
@karenzone
karenzone requested a review from a team as a code owner July 22, 2024 22:19
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)

@karenzone

Copy link
Copy Markdown
Contributor Author

Please review and comment so that we can get the content right before we generate the files.

@nick-alayil nick-alayil left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread packages/auditd_manager/docs/README.md Outdated
## Session View powered by Auditd Manager [BETA]

The `add_session_metadata` processor for Auditd Manager powers the [Session View](https://www.elastic.co/guide/en/security/current/session-view.html) utility for the Elastic Security Platform.
This feature is in Beta at Elastic Security version 8.15.0.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As is, this package is available on all versions of the stack since 8.7.1. Maybe we should not mention any specific stack version here? If there is a minimum Kibana version required for the session view to work with data from this processor then we should bump the Kibana version constraint of the package.

Instead we should indicate what minimum version of Elastic Agent is required to use the processor. We need to make it clear what version of the Agent is required to use this feature because there are no enforced minimum requirements in Fleet.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If there is a minimum Kibana version required for the session view to work with data from this processor then we should bump the Kibana version constraint of the package.

Good suggestion.

  • Where can we get that info?
  • Where do we bump the Kibana version contraint?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch @andrewkroh. The Kibana session view plugin support reading data from auditbeat / auditd manager datastreams from 8.14 onwards.

So, if we specify the agent version dependency as 8.14+, it would be better since agents running 8.14 or higher are only compatible with the Elastic stack version 8.14 or above. Is that a correct understanding of your message?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think 8.15 is the minimum kibana version that enabled auditbeat session view (or it might have gone in with 8.14). I'm not sure what to do for this, it seems strange if we were to change the minimum version here, when this PR is mainly a doc change. Nothing has really changed within this integration to warrant changing the minimum version

@karenzone, to answer your question, the kibana version is set in packages/auditd_manager/manifest.yml, in the conditions.kibana.version field

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I removed the version statement, but left the BETA tag in the Session View heading.

Comment thread packages/auditd_manager/docs/README.md Outdated
To enable the `add_session_metadata` processor for Auditd Manager:

1. Navigate to the Auditd Manager integration configuration in Kibana.
2. Add the `add_session_metadata` processor configuration under the advanced options section.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should show a complete configuration example that can be pasted into the "Processors" section of the advanced options.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I totally agree

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good suggestion. Who can help with that info?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I assume @andrewkroh is referring to the missing backend configuration.

  - add_session_metadata:
      backend: "auto"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I assume @andrewkroh is referring to the missing backend configuration.

  - add_session_metadata:
      backend: "auto"

That's the correct full example, and I agree it should be added too

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added

@benironside benironside left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Comment thread packages/auditd_manager/_dev/build/docs/README.md Outdated
Comment thread packages/auditd_manager/changelog.yml Outdated
Comment on lines +2 to +6
- version: "1.16.5"
changes:
- description: Doc: Add doc for configuring Auditd Manager for Session View
type: enhancement
link: https://github.com/elastic/integrations/issues/10499

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While this work has been in progress, we've bumped to 1.17.0.
Does this work become 1.17.1?

Comment thread packages/auditd_manager/manifest.yml Outdated
name: auditd_manager
title: "Auditd Manager"
version: "1.16.4"
version: "1.16.5"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ToDo: Resolve conflicts and bump version. Does this become 1.17.1?

@karenzone

karenzone commented Aug 15, 2024 •

Copy link
Copy Markdown
Contributor Author

Next up

  • Review and signoff.
    Please review and approve when appropriate.
  • Resolve conflicts in changelog and manifest.
    Does this update become 1.17.1?
  • Generate and update package.
  • Pass buildkite checks and merge.

@karenzone

Copy link
Copy Markdown
Contributor Author

The content should be correct. We need to decide how to handle versioning, resolve conflicts in the changelog and manifest, and get past buildkite. @mjwolf, will you or somebody on your team please help get one over the finish line?

@mjwolf

mjwolf commented Aug 20, 2024

Copy link
Copy Markdown
Contributor

The content should be correct. We need to decide how to handle versioning, resolve conflicts in the changelog and manifest, and get past buildkite. @mjwolf, will you or somebody on your team please help get one over the finish line?

I can work on getting this to build correctly, do you want me to merge it as soon as it's working?

@elastic-sonarqube

Copy link
Copy Markdown

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @karenzone

@karenzone

Copy link
Copy Markdown
Contributor Author

I can work on getting this to build correctly, do you want me to merge it as soon as it's working?

Yes, please @mjwolf! Let's get this info out to users as soon as possible.
Thank you so much for your help on this. ❤️

@mjwolf
mjwolf merged commit 05bcf86 into elastic:main Aug 21, 2024
@karenzone
karenzone deleted the 10499-auditd-manager branch August 21, 2024 15:39
@karenzone

Copy link
Copy Markdown
Contributor Author

@mjwolf, thank you SO MUCH for your work on the feature and the docs for this.
@nick-alayil, thank you for the nice explanation in the issue. That info was particularly helpful in framing up docs.
Thank you to @andrewkroh and other reviewers who contributed.

@nick-alayil

Copy link
Copy Markdown
Contributor

Thank you @karenzone for your hard work in getting the documentation done, especially given the complexity of the system. I really appreciate the time and effort you put into it.

Thanks to @mjwolf for your great work on the feature and docs, and to @andrewkroh and all the reviewers who contributed. This was truly a team effort, and I’m grateful to everyone involved!

harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 4, 2025
…lastic#10544)

Adds documentation for enabling and configuring the add_session_metadata processor for the Auditd Manager integration. The add_session_metadata processor powers the Session View utility in Elastic Security.

---------

Co-authored-by: Michael Wolf <michael.wolf@elastic.co>
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 5, 2025
…lastic#10544)

Adds documentation for enabling and configuring the add_session_metadata processor for the Auditd Manager integration. The add_session_metadata processor powers the Session View utility in Elastic Security.

---------

Co-authored-by: Michael Wolf <michael.wolf@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:auditd_manager Auditd Manager Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Doc: Update Auditd Manager docs to configure add_session_metadata processor (Session View)

6 participants