-
Notifications
You must be signed in to change notification settings - Fork 5k
Closed
Labels
AuditbeatStalledTeam:Security-Linux PlatformLinux Platform Team in Security SolutionLinux Platform Team in Security Solutionenhancement
Description
Describe the enhancement:
Auditbeat system.process
reports information about running processes. ECS 8.10 added new process fields that hold the associated Linux capabilities. The system.process
module should report the capabilities.
go-sysinfo, which this code already uses, supports fetching this data (source), but the returned strings are not in the exact format expected by ECS.
Describe a specific use case for the enhancement or feature:
Metadata
Metadata
Assignees
Labels
AuditbeatStalledTeam:Security-Linux PlatformLinux Platform Team in Security SolutionLinux Platform Team in Security Solutionenhancement