Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat] Ignore cylance.protect timestamps while testing #20207

Merged
merged 2 commits into from
Jul 23, 2020

Conversation

andrewkroh
Copy link
Member

What does this PR do?

Ignore cylance.protect timestamps while testing. The logs may have syslog timestamps without years so the expected times can change.

Why is it important?

Fixes failing tests.

Checklist

  • My code follows the style guidelines of this project
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works
  • I have added an entry in CHANGELOG.next.asciidoc or CHANGELOG-developer.next.asciidoc.

@andrewkroh andrewkroh added review Filebeat Filebeat needs_backport PR is waiting to be backported to other branches. labels Jul 23, 2020
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Jul 23, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Jul 23, 2020
@andrewkroh andrewkroh force-pushed the bugfix/fb/cylance-timestamps branch from d24cccb to f5b81fb Compare July 23, 2020 15:00
@elasticmachine
Copy link
Collaborator

elasticmachine commented Jul 23, 2020

💔 Build Failed

Pipeline View Test View Changes Artifacts preview

Expand to view the summary

Build stats

  • Build Cause: [Pull request #20207 updated]

  • Start Time: 2020-07-23T15:06:43.844+0000

  • Duration: 57 min 8 sec

Test stats 🧪

Test Results
Failed 0
Passed 4688
Skipped 822
Total 5510

Steps errors

Expand to view the steps failures

  • Name: Mage build test
    • Description: mage build test

    • Duration: 9 min 42 sec

    • Start Time: 2020-07-23T15:29:05.026+0000

    • log

Log output

Expand to view the last 100 lines of log output

[2020-07-23T16:03:07.183Z] + python .ci/scripts/search_system_tests.py
[2020-07-23T16:03:07.378Z] [INFO] system-tests='build/filebeat/build/system-tests'. If no empty then let's create a tarball
[2020-07-23T16:03:08.118Z] + tar --version
[2020-07-23T16:03:09.025Z] + tar --exclude=filebeat--system-tests-darwin.tgz -czf filebeat--system-tests-darwin.tgz build/filebeat/build/system-tests
[2020-07-23T16:03:10.152Z] Archiving artifacts
[2020-07-23T16:03:16.047Z] + .ci/scripts/report-codecov.sh auditbeat filebeat heartbeat journalbeat libbeat metricbeat packetbeat winlogbeat
[2020-07-23T16:03:16.047Z] + CODECOV_URL=https://codecov.io/bash
[2020-07-23T16:03:16.047Z] + '[' -e /usr/local/bin/bash_standard_lib.sh ']'
[2020-07-23T16:03:16.047Z] + curl -sSLo codecov https://codecov.io/bash
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=auditbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f auditbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=filebeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f filebeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=heartbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f heartbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=journalbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f journalbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=libbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f libbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=metricbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f metricbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=packetbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f packetbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:16.189Z] + for i in '"$@"'
[2020-07-23T16:03:16.189Z] + FILE=winlogbeat/build/coverage/full.cov
[2020-07-23T16:03:16.189Z] + '[' -f winlogbeat/build/coverage/full.cov ']'
[2020-07-23T16:03:17.260Z] Post stage
[2020-07-23T16:03:17.268Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats
[2020-07-23T16:03:18.076Z] Starting "default"...
[2020-07-23T16:03:18.076Z] Machine "default" is already running.
[2020-07-23T16:03:19.561Z] Error checking TLS connection: Error checking and/or regenerating the certs: There was an error validating certificates for host "192.168.99.102:2376": dial tcp 192.168.99.102:2376: connect: connection refused
[2020-07-23T16:03:19.561Z] You can attempt to regenerate them using 'docker-machine regenerate-certs [name]'.
[2020-07-23T16:03:19.561Z] Be advised that this will trigger a Docker daemon restart which might stop running containers.
[2020-07-23T16:03:19.561Z] 
[2020-07-23T16:03:19.561Z] Client:
[2020-07-23T16:03:19.561Z]  Version:           18.06.1-ce
[2020-07-23T16:03:19.561Z]  API version:       1.38
[2020-07-23T16:03:19.561Z]  Go version:        go1.10.3
[2020-07-23T16:03:19.561Z]  Git commit:        e68fc7a
[2020-07-23T16:03:19.561Z]  Built:             Tue Aug 21 17:21:31 2018
[2020-07-23T16:03:19.561Z]  OS/Arch:           darwin/amd64
[2020-07-23T16:03:19.561Z]  Experimental:      false
[2020-07-23T16:03:19.561Z] Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
[2020-07-23T16:03:19.561Z] It requires Docker daemon to be installed and running
[2020-07-23T16:03:29.972Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats
[2020-07-23T16:03:30.292Z] + find . -type f -name TEST*.xml -path */build/* -delete
[2020-07-23T16:03:30.304Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Lint
[2020-07-23T16:03:30.386Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Filebeat-oss
[2020-07-23T16:03:30.468Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Filebeat-Windows
[2020-07-23T16:03:30.555Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Filebeat-x-pack-Windows
[2020-07-23T16:03:30.633Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Filebeat-x-pack
[2020-07-23T16:03:30.710Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Filebeat-x-pack-Mac-OS-X
[2020-07-23T16:03:30.788Z] Running in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats/Filebeat-Mac-OS-X
[2020-07-23T16:03:31.168Z] + cat
[2020-07-23T16:03:31.168Z] + /usr/local/bin/runbld ./runbld-script
[2020-07-23T16:03:31.168Z] Picked up JAVA_TOOL_OPTIONS: -Dfile.encoding=UTF8
[2020-07-23T16:03:37.761Z] runbld>>> runbld started
[2020-07-23T16:03:37.761Z] runbld>>> 1.6.12/f45d832f2ba0aa2722ab4ec1fda8ad140f027f8b
[2020-07-23T16:03:38.704Z] runbld>>> The following profiles matched the job 'Beats/beats/PR-20207' in order of occurrence in the config (last value wins).
[2020-07-23T16:03:40.089Z] runbld>>> Debug logging enabled.
[2020-07-23T16:03:40.089Z] runbld>>> Storing result
[2020-07-23T16:03:40.366Z] runbld>>> Store result: created {:total 2, :successful 2, :failed 0} 1
[2020-07-23T16:03:40.366Z] runbld>>> BUILD: https://c150076387b5421f9154dfbf536e5c60.us-west1.gcp.cloud.es.io:9243/build-1587637540455/t/20200723160339-9CFE7ABD
[2020-07-23T16:03:40.366Z] runbld>>> Adding system facts.
[2020-07-23T16:03:41.309Z] runbld>>> Adding vcs info for the latest commit:  e25d6c8dff3233c4fa9bf06d89ee69bc732e23a0
[2020-07-23T16:03:41.309Z] runbld>>> >>>>>>>>>>>> SCRIPT EXECUTION BEGIN >>>>>>>>>>>>
[2020-07-23T16:03:41.309Z] runbld>>> Adding /usr/lib/jvm/java-8-openjdk-amd64/bin to the path.
[2020-07-23T16:03:41.309Z] + echo 'Processing JUnit reports with runbld...'
[2020-07-23T16:03:41.309Z] Processing JUnit reports with runbld...
[2020-07-23T16:03:41.570Z] runbld>>> <<<<<<<<<<<< SCRIPT EXECUTION END <<<<<<<<<<<<
[2020-07-23T16:03:41.570Z] runbld>>> DURATION: 22ms
[2020-07-23T16:03:41.570Z] runbld>>> STDOUT: 40 bytes
[2020-07-23T16:03:41.570Z] runbld>>> STDERR: 49 bytes
[2020-07-23T16:03:41.570Z] runbld>>> WRAPPED PROCESS: SUCCESS (0)
[2020-07-23T16:03:41.570Z] runbld>>> Searching for build metadata in /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats
[2020-07-23T16:03:42.968Z] runbld>>> Storing build metadata: 
[2020-07-23T16:03:42.968Z] runbld>>> Adding test report.
[2020-07-23T16:03:42.968Z] runbld>>> Searching for junit test output files with the pattern: TEST-.*\.xml$ in: /var/lib/jenkins/workspace/Beats_beats_PR-20207/src/github.com/elastic/beats
[2020-07-23T16:03:43.539Z] runbld>>> Found 14 test output files
[2020-07-23T16:03:44.928Z] runbld>>> Test output logs contained: Errors: 0 Failures: 0 Tests: 5510 Skipped: 797
[2020-07-23T16:03:44.928Z] runbld>>> Storing result
[2020-07-23T16:03:44.928Z] runbld>>> FAILURES: 0
[2020-07-23T16:03:45.189Z] runbld>>> Store result: updated {:total 2, :successful 2, :failed 0} 2
[2020-07-23T16:03:45.189Z] runbld>>> BUILD: https://c150076387b5421f9154dfbf536e5c60.us-west1.gcp.cloud.es.io:9243/build-1587637540455/t/20200723160339-9CFE7ABD
[2020-07-23T16:03:45.449Z] runbld>>> Email notification disabled by environment variable.
[2020-07-23T16:03:45.449Z] runbld>>> Slack notification disabled by environment variable.
[2020-07-23T16:03:50.997Z] Running on Jenkins in /var/lib/jenkins/workspace/Beats_beats_PR-20207
[2020-07-23T16:03:51.120Z] [INFO] getVaultSecret: Getting secrets
[2020-07-23T16:03:51.206Z] Masking supported pattern matches of $VAULT_ADDR or $VAULT_ROLE_ID or $VAULT_SECRET_ID
[2020-07-23T16:03:51.989Z] + chmod 755 generate-build-data.sh
[2020-07-23T16:03:51.989Z] + ./generate-build-data.sh https://beats-ci.elastic.co/blue/rest/organizations/jenkins/pipelines/Beats/beats/PR-20207/ https://beats-ci.elastic.co/blue/rest/organizations/jenkins/pipelines/Beats/beats/PR-20207/runs/2 FAILURE 3427885
[2020-07-23T16:03:51.989Z] INFO: curl https://beats-ci.elastic.co/blue/rest/organizations/jenkins/pipelines/Beats/beats/PR-20207/runs/2/steps/?limit=10000 -o steps-info.json
[2020-07-23T16:03:52.540Z] INFO: curl https://beats-ci.elastic.co/blue/rest/organizations/jenkins/pipelines/Beats/beats/PR-20207/runs/2/tests/?status=FAILED -o tests-errors.json

@andrewkroh andrewkroh merged commit ddf8c02 into elastic:master Jul 23, 2020
adriansr pushed a commit to adriansr/beats that referenced this pull request Jul 23, 2020
…0207)

* Ignore cylance.protect timestamps while testing

* Update generated

(cherry picked from commit ddf8c02)
@adriansr adriansr added v7.10.0 and removed needs_backport PR is waiting to be backported to other branches. labels Jul 23, 2020
adriansr pushed a commit to adriansr/beats that referenced this pull request Jul 23, 2020
…0207)

* Ignore cylance.protect timestamps while testing

* Update generated

(cherry picked from commit ddf8c02)
adriansr added a commit that referenced this pull request Jul 23, 2020
…20216)

* Ignore cylance.protect timestamps while testing

* Update generated

(cherry picked from commit ddf8c02)

Co-authored-by: Andrew Kroh <[email protected]>
adriansr added a commit that referenced this pull request Jul 23, 2020
…20217)

* Ignore cylance.protect timestamps while testing

* Update generated

(cherry picked from commit ddf8c02)

Co-authored-by: Andrew Kroh <[email protected]>
v1v added a commit to v1v/beats that referenced this pull request Jul 27, 2020
…ne-2.0

* upstream/master: (41 commits)
  adding possibility to override content-type checks, it was breaking certain webhooks that is not able to set content-headers at all. Still defaults to application/json (elastic#20232)
  fix: use a fixed worker type for tests (elastic#20130)
  [Ingest Manager] Prepare packaging for endpoint and asc files (elastic#20186)
  [Packetbeat] HTTP: Improve support for 100-continue elastic#15830 (elastic#19349)
  Increase index.max_docvalue_fields_search to 200 (elastic#20218)
  [Ingest Manager] Prevent closing closed reader (elastic#20214)
  [Metricbeat] Use MySQL Host Parser in Query metricset (elastic#20191)
  Testing: Ignore timestamp from cylance/protect dataset (elastic#20211)
  [Filebeat] Ignore cylance.protect timestamps while testing (elastic#20207)
  [CI] remove codecov step (elastic#20102)
  [docs] Indicate that SYSTEM user is required on Windows to use Endpoint (elastic#20172)
  Remove f5/firepass rsa2elk fileset (elastic#20160)
  [Elastic Agent] Improve GRPC stop to be more relaxed. (elastic#20118)
  Fix fileset field prefixing (elastic#20170)
  Fix terminating pod autodiscover issue (elastic#20084)
  Call host parser only once when building light metricsets (elastic#20149)
  [CI] fix null string with contains (elastic#20182)
  [Ingest Manager] Fix failing unit tests on windows (elastic#20127)
  [Filebeat] Update crowdstrike module (elastic#20138)
  [docs] Add x-pack role to relevant metricsets (elastic#20167)
  ...
v1v added a commit to v1v/beats that referenced this pull request Jul 29, 2020
* upstream/7.9: (32 commits)
  feat(ci): support storing artifacts for PRs in separate dirs (elastic#20282) (elastic#20301)
  Cisco ASA: Fix message 106100 (elastic#20245) (elastic#20277)
  [CI] Change upstream reference (elastic#20296) (elastic#20297)
  [docs] Fix Windows download link for agent (elastic#20258) (elastic#20290)
  Cherry-pick to 7.9: [docs] Rename release highlights to what's new (elastic#20255) (elastic#20285)
  Elastic agent on k8s (elastic#19727) (elastic#20262)
  [Filebeat Module] Defender ATP - Adding dashboard (elastic#20058) (elastic#20093)
  fix: use a fixed worker type for tests (elastic#20130) (elastic#20247)
  [Elastic Agent] Fix Windows powershell install service script (elastic#20203) (elastic#20252)
  [Ingest Manager] Fixed unzip on older windows  (elastic#20088) (elastic#20109)
  adding possibility to override content-type checks, it was breaking certain webhooks that is not able to set content-headers at all. Still defaults to application/json (elastic#20232) (elastic#20237)
  [Filebeat][Gsuite] Make GSuite docs more clear (elastic#19981) (elastic#20067)
  Increase index.max_docvalue_fields_search to 200 (elastic#20218) (elastic#20221)
  Call host parser only once when building light metricsets (elastic#20149) (elastic#20190)
  [Metricbeat] Use MySQL Host Parser in Query metricset (elastic#20191) (elastic#20212)
  [Filebeat] Ignore cylance.protect timestamps while testing (elastic#20207) (elastic#20217)
  [libbeat] Fix write error in ensureWriter.Write (elastic#20112) (elastic#20145)
  Cherry-pick elastic#20127 to 7.9: Fix failing unit tests on windows  (elastic#20180)
  Remove f5/firepass rsa2elk fileset (elastic#20160) (elastic#20206)
  Cherry-pick elastic#20138 to 7.9: [Filebeat] Update crowdstrike module (elastic#20177)
  ...
melchiormoulin pushed a commit to melchiormoulin/beats that referenced this pull request Oct 14, 2020
…0207)

* Ignore cylance.protect timestamps while testing

* Update generated
leweafan pushed a commit to leweafan/beats that referenced this pull request Apr 28, 2023
…0207) (elastic#20217)

* Ignore cylance.protect timestamps while testing

* Update generated

(cherry picked from commit 9c342be)

Co-authored-by: Andrew Kroh <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants