Repository navigation
[Auditd Manager] Add docs to support add_session_metadata processor - #10544
Conversation
4524a70 to
ec5ae34
Compare
ec5ae34 to
480c5cd
Compare
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
|
Please review and comment so that we can get the content right before we generate the files. |
| ## Session View powered by Auditd Manager [BETA] | ||
|
|
||
| The `add_session_metadata` processor for Auditd Manager powers the [Session View](https://www.elastic.co/guide/en/security/current/session-view.html) utility for the Elastic Security Platform. | ||
| This feature is in Beta at Elastic Security version 8.15.0. |
There was a problem hiding this comment.
As is, this package is available on all versions of the stack since 8.7.1. Maybe we should not mention any specific stack version here? If there is a minimum Kibana version required for the session view to work with data from this processor then we should bump the Kibana version constraint of the package.
Instead we should indicate what minimum version of Elastic Agent is required to use the processor. We need to make it clear what version of the Agent is required to use this feature because there are no enforced minimum requirements in Fleet.
There was a problem hiding this comment.
If there is a minimum Kibana version required for the session view to work with data from this processor then we should bump the Kibana version constraint of the package.
Good suggestion.
- Where can we get that info?
- Where do we bump the Kibana version contraint?
There was a problem hiding this comment.
Good catch @andrewkroh. The Kibana session view plugin support reading data from auditbeat / auditd manager datastreams from 8.14 onwards.
So, if we specify the agent version dependency as 8.14+, it would be better since agents running 8.14 or higher are only compatible with the Elastic stack version 8.14 or above. Is that a correct understanding of your message?
There was a problem hiding this comment.
I think 8.15 is the minimum kibana version that enabled auditbeat session view (or it might have gone in with 8.14). I'm not sure what to do for this, it seems strange if we were to change the minimum version here, when this PR is mainly a doc change. Nothing has really changed within this integration to warrant changing the minimum version
@karenzone, to answer your question, the kibana version is set in packages/auditd_manager/manifest.yml, in the conditions.kibana.version field
There was a problem hiding this comment.
I removed the version statement, but left the BETA tag in the Session View heading.
| To enable the `add_session_metadata` processor for Auditd Manager: | ||
|
|
||
| 1. Navigate to the Auditd Manager integration configuration in Kibana. | ||
| 2. Add the `add_session_metadata` processor configuration under the advanced options section. |
There was a problem hiding this comment.
We should show a complete configuration example that can be pasted into the "Processors" section of the advanced options.
There was a problem hiding this comment.
Good suggestion. Who can help with that info?
There was a problem hiding this comment.
I assume @andrewkroh is referring to the missing backend configuration.
- add_session_metadata:
backend: "auto"
There was a problem hiding this comment.
I assume @andrewkroh is referring to the missing
backendconfiguration.- add_session_metadata: backend: "auto"
That's the correct full example, and I agree it should be added too
| - version: "1.16.5" | ||
| changes: | ||
| - description: Doc: Add doc for configuring Auditd Manager for Session View | ||
| type: enhancement | ||
| link: https://github.com/elastic/integrations/issues/10499 |
There was a problem hiding this comment.
While this work has been in progress, we've bumped to 1.17.0.
Does this work become 1.17.1?
| name: auditd_manager | ||
| title: "Auditd Manager" | ||
| version: "1.16.4" | ||
| version: "1.16.5" |
There was a problem hiding this comment.
ToDo: Resolve conflicts and bump version. Does this become 1.17.1?
Next up
|
|
The content should be correct. We need to decide how to handle versioning, resolve conflicts in the changelog and manifest, and get past buildkite. @mjwolf, will you or somebody on your team please help get one over the finish line? |
I can work on getting this to build correctly, do you want me to merge it as soon as it's working? |
|
💚 Build Succeeded
History
cc @karenzone |
Yes, please @mjwolf! Let's get this info out to users as soon as possible. |
|
@mjwolf, thank you SO MUCH for your work on the feature and the docs for this. |
|
Thank you @karenzone for your hard work in getting the documentation done, especially given the complexity of the system. I really appreciate the time and effort you put into it. Thanks to @mjwolf for your great work on the feature and docs, and to @andrewkroh and all the reviewers who contributed. This was truly a team effort, and I’m grateful to everyone involved! |
…lastic#10544) Adds documentation for enabling and configuring the add_session_metadata processor for the Auditd Manager integration. The add_session_metadata processor powers the Session View utility in Elastic Security. --------- Co-authored-by: Michael Wolf <michael.wolf@elastic.co>
…lastic#10544) Adds documentation for enabling and configuring the add_session_metadata processor for the Auditd Manager integration. The add_session_metadata processor powers the Session View utility in Elastic Security. --------- Co-authored-by: Michael Wolf <michael.wolf@elastic.co>




Adds documentation for enabling and configuring the
add_session_metadataprocessor for the Auditd Manager integration. Theadd_session_metadataprocessor powers the Session View utility in Elastic Security.Related: elastic/beats#40186
Closes: #10499