Skip to content

Add entity_id for process and process.parent#747

Merged
webmat merged 2 commits intoelastic:masterfrom
andrewstucki:entity_id
Feb 18, 2020
Merged

Add entity_id for process and process.parent#747
webmat merged 2 commits intoelastic:masterfrom
andrewstucki:entity_id

Conversation

@andrewstucki
Copy link
Copy Markdown
Contributor

This implements the unique process identification field discussed in #672. We settled on allowing ECS users to use their own implementation-specific values in this field in order to support multiple types of data shippers that may have different requirements around the identifier generation. That said, there's still room for future discussion on some sort of standard generation algorithm that would allow us to correlate processes across multiple sources.

The name corresponds to what beats are already filling in for their unique identifier.

Copy link
Copy Markdown
Contributor

@webmat webmat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggesting a minor addition to the description.

But I'm good with this in any case. Thanks @andrewstucki!

@webmat
Copy link
Copy Markdown
Contributor

webmat commented Feb 14, 2020

And 👍 on keeping the Beats field name.

@webmat
Copy link
Copy Markdown
Contributor

webmat commented Feb 14, 2020

Oof, second ☕️ hasn't kicked in yet, it seems.

Another request: please add a changelog entry :-)

Copy link
Copy Markdown
Contributor

@webmat webmat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great, LGTM!

@webmat
Copy link
Copy Markdown
Contributor

webmat commented Feb 14, 2020

Let's wait for @rw-access to chime in as well. You can merge after that :-)

Copy link
Copy Markdown
Contributor

@rw-access rw-access left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@webmat webmat merged commit feb6a46 into elastic:master Feb 18, 2020
@andrewstucki andrewstucki deleted the entity_id branch February 18, 2020 16:50
webmat pushed a commit to webmat/ecs that referenced this pull request Mar 4, 2020
- code_signature (elastic#733)
- second entry for elastic#739 in the schema section, mentioning the addition of `process.parent.hash`

Also adjusted the wording of elastic#731 and elastic#747.
dcode pushed a commit to dcode/ecs that referenced this pull request Apr 15, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants