Skip to content

[Auditd_Manager] fixing wrong field type for auditd.data.exit - #6111

Merged
P1llus merged 4 commits into
elastic:mainfrom
P1llus:package_auditdmanager_dataexit
May 9, 2023
Merged

P1llus merged 4 commits into
elastic:mainfrom
P1llus:package_auditdmanager_dataexit

Conversation

@P1llus

@P1llus P1llus commented May 5, 2023 •

Copy link
Copy Markdown
Member

What does this PR do?

Fixes wrong field type for auditd.data.exit. It was keyword in auditbeat and seems to convert to a keyword/string value if the integer value is known, or the exit code is a string by itself.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Related issues

@P1llus P1llus added bug Something isn't working, use only for issues Team:Security-External Integrations Integration:auditd_manager Auditd Manager labels May 5, 2023
@P1llus
P1llus requested a review from a team as a code owner May 5, 2023 19:22
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@taylor-swanson taylor-swanson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread packages/auditd_manager/changelog.yml Outdated
@elasticmachine

elasticmachine commented May 5, 2023 •

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-05-09T14:11:58.195+0000

  • Duration: 18 min 16 sec

Test stats 🧪

Test Results
Failed 0
Passed 21
Skipped 0
Total 21

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine

elasticmachine commented May 5, 2023 •

Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (1/1) 💚
Files 100.0% (1/1) 💚 50.0
Classes 100.0% (1/1) 💚 50.0
Methods 88.889% (8/9) 👍 19.658
Lines 90.206% (175/194) 👍 19.836
Conditionals 100.0% (0/0) 💚

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs a test expectation update.

@BenB196

BenB196 commented May 8, 2023

Copy link
Copy Markdown
Contributor

(FYI) This looks like it will resolve #4860

@andrewkroh andrewkroh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The exit code is always a string in the JSON from auditbeat. go-libaudit translates numbers to named POSIX exit codes if possible.

@P1llus
P1llus merged commit d49cc05 into elastic:main May 9, 2023
@elasticmachine

Copy link
Copy Markdown

Package auditd_manager - 1.7.1 containing this change is available at https://epr.elastic.co/search?package=auditd_manager

orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
…c#6111)

* fixing wrong field type for auditd.data.exit

* update changelog

* modify changelog type

* Update pipeline tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working, use only for issues Integration:auditd_manager Auditd Manager

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[auditd_manager] Integration can throw illegal_argument_exception

6 participants