Skip to content

auditd_manager: add auditd.data.prog_id field definition - #21250

Merged
efd6 merged 1 commit into
elastic:mainfrom
efd6:14024-auditd_manager
Sep 24, 2026
Merged

efd6 merged 1 commit into
elastic:mainfrom
efd6:14024-auditd_manager

Conversation

@efd6

@efd6 efd6 commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Proposed commit message

auditd_manager: add auditd.data.prog_id field definition

AUDIT_BPF records are emitted when eBPF programs are loaded or unloaded.
These contain a prog-id attribute.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

@efd6 efd6 self-assigned this Sep 14, 2026
@efd6 efd6 added enhancement New feature or request Integration:auditd_manager Auditd Manager Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Sep 14, 2026
AUDIT_BPF records are emitted when eBPF programs are loaded or unloaded.
These contain a prog-id attribute.
@efd6
efd6 force-pushed the 14024-auditd_manager branch from 084483c to 90e9e10 Compare September 14, 2026 22:43
@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

cc @efd6

@efd6
efd6 marked this pull request as ready for review September 14, 2026 23:31
@efd6
efd6 requested a review from a team as a code owner September 14, 2026 23:31
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@vera-review-bot

Copy link
Copy Markdown

🟢 No issues across the latest commits 90e9e10.

A new commit triggers another review — at most once every 15 minutes. I skip the PR while it's approved or has merge conflicts.

🤖 AI-Generated Review | Vera Review Bot - v0.4.1 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@qcorporation qcorporation added the documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. label Sep 15, 2026
@mergify

mergify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

@efd6
efd6 merged commit f9b9512 into elastic:main Sep 24, 2026
10 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package auditd_manager - 1.21.0 containing this change is available at https://epr.elastic.co/package/auditd_manager/1.21.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:auditd_manager Auditd Manager Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[LogsDB] [Subscription basic] [auditd_manager] Failing test daily: system test: default in auditd_manager.auditd

3 participants