Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x-pack/winlogbeat/module/sysmon: add eventid 26 handler #29957

Merged
merged 1 commit into from
Jan 24, 2022

Conversation

efd6
Copy link
Contributor

@efd6 efd6 commented Jan 24, 2022

What does this PR do?

This change adds support for sysmon event ID 26; FileDeleteDetected.

Why is it important?

See linked issue #26280.

Checklist

  • My code follows the style guidelines of this project
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works
  • I have added an entry in CHANGELOG.next.asciidoc or CHANGELOG-developer.next.asciidoc.

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Use cases

See linked issue.

Screenshots

Test event 1:
Screen Shot 2022-01-24 at 15 47 33

Test event 2:
Screen Shot 2022-01-24 at 15 46 54

Logs

See screenshot above.

@efd6 efd6 requested a review from a team as a code owner January 24, 2022 06:03
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Jan 24, 2022
@mergify
Copy link
Contributor

mergify bot commented Jan 24, 2022

This pull request does not have a backport label. Could you fix it @efd6? 🙏
To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • backport-v./d./d./d is the label to automatically backport to the 7./d branch. /d is the digit

NOTE: backport-skip has been added to this pull request.

@mergify mergify bot added the backport-skip Skip notification from the automated backport with mergify label Jan 24, 2022
@efd6 efd6 marked this pull request as draft January 24, 2022 06:03
@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Jan 24, 2022
@mergify mergify bot removed the backport-skip Skip notification from the automated backport with mergify label Jan 24, 2022
@efd6 efd6 marked this pull request as ready for review January 24, 2022 06:58
@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@efd6 efd6 requested a review from leehinman January 24, 2022 06:58
@elasticmachine
Copy link
Collaborator

elasticmachine commented Jan 24, 2022

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2022-01-24T06:15:49.178+0000

  • Duration: 58 min 47 sec

  • Commit: 345e3b8

Test stats 🧪

Test Results
Failed 0
Passed 27
Skipped 0
Total 27

💚 Flaky test report

Tests succeeded.

🤖 GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

  • /package : Generate the packages and run the E2E tests.

  • /beats-tester : Run the installation tests with beats-tester.

  • run elasticsearch-ci/docs : Re-trigger the docs validation. (use unformatted text in the comment!)

@efd6 efd6 merged commit 33acb3c into elastic:master Jan 24, 2022
mergify bot pushed a commit that referenced this pull request Jan 24, 2022
@efd6 efd6 deleted the sysmon26 branch January 24, 2022 20:42
efd6 added a commit that referenced this pull request Jan 25, 2022
yashtewari pushed a commit to build-security/beats that referenced this pull request Jan 30, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
8.1-candidate backport-v8.0.0 Automated backport with mergify enhancement
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Winlogbeat] Update Sysmon module for Schema 4.70 that includes Event ID 26
3 participants