Skip to content

Cherry-pick #15621 to 7.x: Cherry-pick #14553 to 7.6: New fileset for googlecloud firewall logs#15625

Merged
adriansr merged 1 commit intoelastic:7.xfrom
adriansr:backport_15621_7.x
Jan 17, 2020
Merged

Cherry-pick #15621 to 7.x: Cherry-pick #14553 to 7.6: New fileset for googlecloud firewall logs#15625
adriansr merged 1 commit intoelastic:7.xfrom
adriansr:backport_15621_7.x

Conversation

@adriansr
Copy link
Copy Markdown
Contributor

Cherry-pick of PR #15621 to 7.x branch. Original message:

Cherry-pick of PR #14553 and related #14608 to 7.6 branch. Original message:

This PR adds a new fileset, firewall, to the googlecloud module in Filebeat. It helps parsing firewall logs generated by rules under VPC Network -> Firewall Rules.

Note that GCP only logs firewall events under the following conditions:

Logging needs to be enabled for each individual rule in order to log.
Only TCP and UDP rules can be logged.

See https://cloud.google.com/vpc/docs/using-firewall-rules-logging.

…l logs (elastic#15621)

* New fileset for googlecloud firewall logs (elastic#14553)

This PR adds a new fileset, firewall, to the googlecloud module in Filebeat. It helps
parsing firewall logs generated by rules under VPC Network -> Firewall Rules.

Note that GCP only logs firewall events under the following conditions:
- Logging needs to be enabled for each individual rule in order to log.
- Only TCP and UDP rules can be logged.

(cherry picked from commit 4a66f0b)

* googlecloud/vpcflow fileset: Populate additional log fields (elastic#14608)

To keep the vpcflow fileset of the googlecloud module aligned with the
new firewall fileset, a `var.keep_original_message` option is added.
Also the log.logger ECS field is now filled.

(cherry picked from commit 22fb66d)
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/siem (Team:SIEM)

@adriansr adriansr merged commit 5b91f87 into elastic:7.x Jan 17, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants