Skip to content

Commit 0293e71

Browse files
Add linux capabilities to process events (#431)
* Add linux capabilities to process events * Update year * Ignore vim temp files * Update ECS_GIT_REF to v8.10.0 * Ensure caps are included in our custom ECS subset * Add results of make * adding the results of make -B
1 parent 8c8621b commit 0293e71

File tree

52 files changed

+658
-200
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

52 files changed

+658
-200
lines changed

.gitignore

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,3 +8,4 @@ venv/
88
vendor/
99
generated/
1010
.DS_Store
11+
*.swp

Makefile

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
ROOT_DIR := $(shell dirname $(realpath $(firstword $(MAKEFILE_LIST))))
22
# we are intentionally pinning the ECS version here, when ecs releases a new version
33
# we'll discuss whether we need to release a new package and bump the version here
4-
# cd3227cb3eb0de7e422aef90a64321ac68f7896e is 8.7-dev
5-
ECS_GIT_REF ?= cd3227cb3eb0de7e422aef90a64321ac68f7896e
4+
# 43a1a61a4a4db88e2de60da9019733610717ff7e is v8.10.0
5+
ECS_GIT_REF ?= 43a1a61a4a4db88e2de60da9019733610717ff7e
6+
67

78
# This variable specifies to location of the package-storage repo. It is used for automatically creating a PR
89
# to release a new endpoint package. This can be overridden with the location on your file system using the config.mk

NOTICE.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
Elastic Endpoint Package
2-
Copyright 2017-2019 Elasticsearch B.V.
2+
Copyright 2017-2023 Elasticsearch B.V.
33

44
This product includes software developed at
55
Elasticsearch, B.V. (https://www.elastic.co/).

custom_documentation/doc/endpoint/process/linux/linux_process_already_running.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -181,6 +181,8 @@ This event is generated for a process that was already running before Endpoint's
181181
| process.start |
182182
| process.supplemental_groups.id |
183183
| process.supplemental_groups.name |
184+
| process.thread.capabilities.permitted |
185+
| process.thread.capabilities.effective |
184186
| process.tty.char_device.major |
185187
| process.tty.char_device.minor |
186188
| process.user.id |

custom_documentation/doc/endpoint/process/linux/linux_process_exec.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -186,6 +186,8 @@ This event is generated when a process calls `exec()`.
186186
| process.start |
187187
| process.supplemental_groups.id |
188188
| process.supplemental_groups.name |
189+
| process.thread.capabilities.permitted |
190+
| process.thread.capabilities.effective |
189191
| process.tty.char_device.major |
190192
| process.tty.char_device.minor |
191193
| process.user.id |

custom_documentation/doc/endpoint/process/linux/linux_process_exit.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,8 @@ This event is generated when a process exits.
9494
| process.entry_leader.start |
9595
| process.entry_leader.supplemental_groups.id |
9696
| process.entry_leader.supplemental_groups.name |
97+
| process.thread.capabilities.permitted |
98+
| process.thread.capabilities.effective |
9799
| process.entry_leader.tty.char_device.major |
98100
| process.entry_leader.tty.char_device.minor |
99101
| process.entry_leader.user.id |

custom_documentation/doc/endpoint/process/linux/linux_process_fork.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -183,6 +183,8 @@ This event is generated when a new process is created using `fork()`.
183183
| process.start |
184184
| process.supplemental_groups.id |
185185
| process.supplemental_groups.name |
186+
| process.thread.capabilities.permitted |
187+
| process.thread.capabilities.effective |
186188
| process.tty.char_device.major |
187189
| process.tty.char_device.minor |
188190
| process.user.id |

custom_documentation/doc/endpoint/process/linux/linux_process_gid_change.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -184,6 +184,8 @@ This event is generated when the group id changes for a process.
184184
| process.start |
185185
| process.supplemental_groups.id |
186186
| process.supplemental_groups.name |
187+
| process.thread.capabilities.permitted |
188+
| process.thread.capabilities.effective |
187189
| process.tty.char_device.major |
188190
| process.tty.char_device.minor |
189191
| process.user.id |

custom_documentation/doc/endpoint/process/linux/linux_process_session_id_change.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -181,6 +181,8 @@ This event is generated when a process's session id changes.
181181
| process.start |
182182
| process.supplemental_groups.id |
183183
| process.supplemental_groups.name |
184+
| process.thread.capabilities.permitted |
185+
| process.thread.capabilities.effective |
184186
| process.tty.char_device.major |
185187
| process.tty.char_device.minor |
186188
| process.user.id |

custom_documentation/doc/endpoint/process/linux/linux_process_text_output.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,8 @@ This event is generated when a process generates text output.
182182
| process.start |
183183
| process.supplemental_groups.id |
184184
| process.supplemental_groups.name |
185+
| process.thread.capabilities.permitted |
186+
| process.thread.capabilities.effective |
185187
| process.tty.char_device.major |
186188
| process.tty.char_device.minor |
187189
| process.tty.columns |

0 commit comments

Comments
 (0)