Skip to content

Commit bcb83e8

Browse files
authored
Filebeat tests: Restore @timestamp field validation (#29772)
This restores the `@timestamp` field in Filebeat's module tests, so that it is properly validated. Temporarily disable timestamp validation in ibmmq module
1 parent 5e3c358 commit bcb83e8

36 files changed

+569
-35
lines changed

filebeat/module/apache/error/test/sublevel.log-expected.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,4 +18,4 @@
1818
"process.thread.id": 140413273032448,
1919
"service.type": "apache"
2020
}
21-
]
21+
]

filebeat/module/auditd/log/test/audit-cent7-node.log-expected.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
[
22
{
3+
"@timestamp": "2020-07-06T16:38:34.588Z",
34
"auditd.log.format": "raw",
45
"auditd.log.kernel": "3.10.0-1062.9.1.el7.x86_64",
56
"auditd.log.node": "localhost.localdomain",
@@ -32,6 +33,7 @@
3233
"user.id": "0"
3334
},
3435
{
36+
"@timestamp": "2020-07-06T16:38:34.707Z",
3537
"auditd.log.audit_backlog_limit": "8192",
3638
"auditd.log.node": "localhost.localdomain",
3739
"auditd.log.old": "64",
@@ -61,6 +63,7 @@
6163
"user.audit.id": "4294967295"
6264
},
6365
{
66+
"@timestamp": "2020-07-06T16:38:34.707Z",
6467
"auditd.log.audit_failure": "1",
6568
"auditd.log.node": "localhost.localdomain",
6669
"auditd.log.old": "1",
@@ -90,6 +93,7 @@
9093
"user.audit.id": "4294967295"
9194
},
9295
{
96+
"@timestamp": "2020-07-06T16:38:34.709Z",
9397
"auditd.log.node": "localhost.localdomain",
9498
"auditd.log.record_type": "SERVICE_START",
9599
"auditd.log.sequence": 6,
@@ -121,6 +125,7 @@
121125
"user.id": "0"
122126
},
123127
{
128+
"@timestamp": "2020-07-06T16:38:34.725Z",
124129
"auditd.log.node": "localhost.localdomain",
125130
"auditd.log.record_type": "SYSTEM_BOOT",
126131
"auditd.log.sequence": 7,
@@ -147,6 +152,7 @@
147152
"user.id": "0"
148153
},
149154
{
155+
"@timestamp": "2020-07-06T16:38:34.739Z",
150156
"auditd.log.node": "localhost.localdomain",
151157
"auditd.log.record_type": "SERVICE_START",
152158
"auditd.log.sequence": 8,
@@ -178,6 +184,7 @@
178184
"user.id": "0"
179185
},
180186
{
187+
"@timestamp": "2020-07-06T16:38:34.807Z",
181188
"auditd.log.node": "localhost.localdomain",
182189
"auditd.log.record_type": "SERVICE_START",
183190
"auditd.log.sequence": 9,
@@ -209,6 +216,7 @@
209216
"user.id": "0"
210217
},
211218
{
219+
"@timestamp": "2020-07-06T16:38:34.843Z",
212220
"auditd.log.node": "localhost.localdomain",
213221
"auditd.log.record_type": "SERVICE_START",
214222
"auditd.log.sequence": 10,
@@ -240,6 +248,7 @@
240248
"user.id": "0"
241249
},
242250
{
251+
"@timestamp": "2020-07-06T16:38:34.850Z",
243252
"auditd.log.node": "localhost.localdomain",
244253
"auditd.log.record_type": "SERVICE_START",
245254
"auditd.log.sequence": 11,
@@ -271,6 +280,7 @@
271280
"user.id": "0"
272281
},
273282
{
283+
"@timestamp": "2020-07-06T16:38:34.857Z",
274284
"auditd.log.node": "localhost.localdomain",
275285
"auditd.log.record_type": "SERVICE_START",
276286
"auditd.log.sequence": 12,

filebeat/module/auditd/log/test/audit-rhel6.log-expected.json

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
[
22
{
3+
"@timestamp": "2017-03-14T19:20:30.178Z",
34
"auditd.log.op": "PAM:session_close",
45
"auditd.log.record_type": "USER_END",
56
"auditd.log.sequence": 19600327,
@@ -31,6 +32,7 @@
3132
"user.name": "root"
3233
},
3334
{
35+
"@timestamp": "2017-03-14T19:20:30.178Z",
3436
"auditd.log.op": "PAM:setcred",
3537
"auditd.log.record_type": "CRED_DISP",
3638
"auditd.log.sequence": 19600328,
@@ -62,6 +64,7 @@
6264
"user.name": "root"
6365
},
6466
{
67+
"@timestamp": "2017-03-14T19:20:56.192Z",
6568
"auditd.log.record_type": "USER_CMD",
6669
"auditd.log.sequence": 19600329,
6770
"auditd.log.ses": "11988",
@@ -95,6 +98,7 @@
9598
"user.id": "497"
9699
},
97100
{
101+
"@timestamp": "2017-03-14T19:20:56.193Z",
98102
"auditd.log.op": "PAM:setcred",
99103
"auditd.log.record_type": "CRED_ACQ",
100104
"auditd.log.sequence": 19600330,
@@ -126,6 +130,7 @@
126130
"user.name": "root"
127131
},
128132
{
133+
"@timestamp": "2017-03-14T19:20:56.193Z",
129134
"auditd.log.op": "PAM:session_open",
130135
"auditd.log.record_type": "USER_START",
131136
"auditd.log.sequence": 19600331,
@@ -157,6 +162,7 @@
157162
"user.name": "root"
158163
},
159164
{
165+
"@timestamp": "2017-03-14T19:23:02.529Z",
160166
"auditd.log.dst_prefixlen": 22,
161167
"auditd.log.op": "SPD-add",
162168
"auditd.log.sequence": 19600354,
@@ -178,6 +184,7 @@
178184
"user.audit.id": "4294967295"
179185
},
180186
{
187+
"@timestamp": "2017-03-14T19:23:02.529Z",
181188
"auditd.log.a0": "9",
182189
"auditd.log.a1": "7f564ee6d2a0",
183190
"auditd.log.a2": "b8",
@@ -221,6 +228,7 @@
221228
"user.saved.id": "0"
222229
},
223230
{
231+
"@timestamp": "2017-03-16T04:02:40.072Z",
224232
"auditd.log.new_auid": "700",
225233
"auditd.log.new_ses": "12286",
226234
"auditd.log.old_auid": "700",
@@ -250,6 +258,7 @@
250258
"user.id": "700"
251259
},
252260
{
261+
"@timestamp": "2017-03-16T04:02:40.070Z",
253262
"auditd.log.direction": "both",
254263
"auditd.log.kind": "session",
255264
"auditd.log.laddr": "107.170.139.210",
@@ -296,6 +305,7 @@
296305
"user.saved.id": "74"
297306
},
298307
{
308+
"@timestamp": "2017-03-16T04:02:40.072Z",
299309
"auditd.log.op": "success",
300310
"auditd.log.record_type": "USER_AUTH",
301311
"auditd.log.sequence": 19623789,
@@ -339,6 +349,7 @@
339349
"user.terminal": "ssh"
340350
},
341351
{
352+
"@timestamp": "2017-03-16T04:02:57.804Z",
342353
"auditd.log.op": "PAM:authentication",
343354
"auditd.log.record_type": "USER_AUTH",
344355
"auditd.log.sequence": 19623807,
@@ -371,6 +382,7 @@
371382
"user.terminal": "pts/0"
372383
},
373384
{
385+
"@timestamp": "2017-03-16T04:02:57.805Z",
374386
"auditd.log.op": "PAM:accounting",
375387
"auditd.log.record_type": "USER_ACCT",
376388
"auditd.log.sequence": 19623808,

0 commit comments

Comments
 (0)