Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions packages/auditd_manager/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,12 @@
# newer versions go on top
- version: "1.2.0"
changes:
- description: Expose `immutable` option.
type: enhancement
link: https://github.com/elastic/integrations/pull/3760
- description: Change audit rules to be a textarea instead of a list.
type: enhancement
link: https://github.com/elastic/integrations/pull/3760
- version: "1.1.0"
changes:
- description: Update package to ECS 8.3.0.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,16 +1,17 @@
data_stream:
vars:
audit_rules:
- -a always,exit -F arch=b64 -S execve,execveat -k exec
- -a always,exit -F arch=b64 -S accept,bind,connect -F key=external-access
- -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -k access
- -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -k access
- -w /etc/group -p wa -k identity
- -w /etc/passwd -p wa -k identity
- -w /etc/gshadow -p wa -k identity
- -w /etc/shadow -p wa -k identity
- -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -F key=access
- -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -F key=access
- -a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -F key=access
- -a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -F key=access
audit_rules: |-
-a always,exit -F arch=b64 -S execve,execveat -k exec
-a always,exit -F arch=b64 -S accept,bind,connect -F key=external-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -k access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -k access
# a comment
-w /etc/group -p wa -k identity
-w /etc/passwd -p wa -k identity
-w /etc/gshadow -p wa -k identity
-w /etc/shadow -p wa -k identity
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -F key=access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -F key=access
-a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -F key=access
-a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -F key=access
preserve_original_event: true
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,11 @@ include_raw_message: true
socket_type: multicast
{{else}}
socket_type: unicast
immutable: {{immutable}}
{{/if}}
resolve_ids: {{resolve_ids}}
failure_mode: {{failure_mode}}
audit_rules: |
{{#each audit_rules as |rule i|}}
{{rule}}
{{/each}}
audit_rules: {{escape_string audit_rules}}
backlog_limit: {{backlog_limit}}
rate_limit: {{rate_limit}}
include_warnings: {{include_warnings}}
Expand Down
17 changes: 15 additions & 2 deletions packages/auditd_manager/data_stream/auditd/manifest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,20 @@ streams:

If it is set to `true`, but the kernel version is less than 3.16 it will be
automatically disabled.
- name: immutable
type: bool
title: Immutable
show_user: true
multi: false
default: false
description: |
This boolean setting sets the audit config as immutable (`-e 2`).
This option can only be used if `multicast` is disabled since `elastic-agent`
needs to manage the rules to be able to set it.

Please note that with this setting enabled, after Elastic Agent restarts or
upgrades, events will continue to be processed but the configuration won't
be updated until the system is restarted entirely.
- name: resolve_ids
type: bool
title: Resolve IDs
Expand All @@ -49,10 +63,9 @@ streams:
`printk` so they show up in system's syslog, and `panic` causes the kernel to
panic to prevent use of the machine.
- name: audit_rules
type: text
type: textarea
title: Audit rules
required: true
multi: true
show_user: true
description: |
List of the audit rules that should be
Expand Down
4 changes: 2 additions & 2 deletions packages/auditd_manager/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 1.0.0
name: auditd_manager
title: "Auditd Manager"
version: "1.1.0"
version: "1.2.0"
release: ga
license: basic
description: "The Auditd Manager Integration receives audit events from the Linux Audit Framework that is a part of the Linux kernel."
Expand All @@ -10,7 +10,7 @@ categories:
- os_system
- security
conditions:
kibana.version: "^8.2.0"
kibana.version: "^8.4.0"
screenshots:
- src: /img/overview.png
title: Overview Dashboard
Expand Down