Skip to content

[auditd_manager] Expose immutable option and rules as textarea - #3760

Merged
marc-gr merged 6 commits into
elastic:mainfrom
marc-gr:feat/auditd-mgr-immut
Jul 27, 2022
Merged

marc-gr merged 6 commits into
elastic:mainfrom
marc-gr:feat/auditd-mgr-immut

Conversation

@marc-gr

@marc-gr marc-gr commented Jul 19, 2022 •

Copy link
Copy Markdown
Contributor

What does this PR do?

  • Exposes the recently added immutable option.
  • Changes audit rules to a textarea instead of a list

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Depends on #3790

@marc-gr
marc-gr requested a review from a team as a code owner July 19, 2022 13:38
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@marc-gr
marc-gr force-pushed the feat/auditd-mgr-immut branch from 53f4ad6 to 3e5618d Compare July 19, 2022 13:38
@elasticmachine

elasticmachine commented Jul 19, 2022 •

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2022-07-27T10:31:24.885+0000

  • Duration: 19 min 35 sec

Test stats 🧪

Test Results
Failed 0
Passed 21
Skipped 0
Total 21

🤖 GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine

elasticmachine commented Jul 19, 2022 •

Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (1/1) 💚
Files 100.0% (1/1) 💚 2.874
Classes 100.0% (1/1) 💚 2.874
Methods 88.889% (8/9) 👎 -0.371
Lines 90.404% (179/198) 👎 -0.182
Conditionals 100.0% (0/0) 💚


It is important to note that with this setting set, the `elastic-agent` should never
be stopped, as it won't be able to resume processing `auditd` events until the
system is restarted.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@marc-gr does this also apply to Elastic Agent upgrades? i.e. if an agent restarts during an upgrade, will the system need to be restarted also to resume auditd event collection?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am afraid so. The process PID is part of the locked config, so once restarted it will be unable to start reading events again until the system is restarted. Please @adriansr correct me here if I am mistaken.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for confirming @marc-gr - we should definitely include it within our docs, as well as in the integration description.

@nimarezainia do you know if agent could check if this option is enabled on hosts running the auditd_manager integration, and inform a user that a restart will be required before they go ahead with the agent upgrade?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jamiehynds lmk if the addition is enough

@jamiehynds jamiehynds Jul 21, 2022 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@marc-gr Could we adjust slightly: Please note that if the immutable setting is enabled and the Elastic Agent on your host is stopped or restarted, a full system restart will be required in order to resume processing of Auditd events. Elastic Agent upgrades will also impact the Auditd event processing, and a system restart will be required during Agent upgrades too.

@jamiehynds jamiehynds Jul 21, 2022 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@marc-gr also, do integration upgrades have an impact too? I assume not as the agent remains running when a user upgrades a package, but just want to be sure.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I do not know about that tbh. Not sure how elastic agent deals with the underlying auditbeat. If the pid does not change it should be alright, if it does, then a restart will be required. Maybe someone from the @elastic/elastic-agent-control-plane can answer this.

@andrewkroh andrewkroh Jul 22, 2022 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It should be possible to set the PID so an auditbeat restart should work. So as long as auditbeat does not fail because it cannot change rules it should work.

I tested restarting auditd on Debian 5.10.127-1 (2022-06-30) x86_64 GNU/Linux after adding -e 2 and I was able to change the PID. I saw messages like

audit: CONFIG_CHANGE op=set audit_pid=1713 old=0 auid=4294967295 ses=4294967295 subj==unconfined res=1
auditd[1713]: Init complete, auditd 3.0 listening for events
auditctl[1726]: The audit system is in immutable mode, no rule changes allowed

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should do a basic manual test by installing an Agent on VM and testing the scenario.

@marc-gr marc-gr Jul 27, 2022 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did some tests and made the required changes to skip configuration setting on auditbeat if immutable is set and the config is locked (elastic/beats#32498). Now after any restart events will continue to come in. Restart of the system will be required to apply any config change. cc @jamiehynds

@marc-gr
marc-gr requested a review from jamiehynds July 21, 2022 07:36
@marc-gr marc-gr changed the title [auditd_manager] Expose immutable option [auditd_manager] Expose immutable option and rules as textarea Jul 22, 2022
@marc-gr
marc-gr requested a review from andrewkroh July 27, 2022 08:10

@adriansr adriansr left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a minor copy suggestion

Comment thread packages/auditd_manager/data_stream/auditd/manifest.yml Outdated

@adriansr adriansr left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@marc-gr
marc-gr merged commit d90c6db into elastic:main Jul 27, 2022
@marc-gr
marc-gr deleted the feat/auditd-mgr-immut branch July 27, 2022 11:13
orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
…stic#3760)

* Expose  option

* Add comment about update process and immutable to docs

* Change audit rules to be a textarea instead of a list.

* Update immutable docs

* Change immutable config title
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:auditd Auditd Logs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants