Skip to content

[Auditbeat] system.process - report Linux capabilities #36404

@andrewkroh

Description

@andrewkroh

Describe the enhancement:

Auditbeat system.process reports information about running processes. ECS 8.10 added new process fields that hold the associated Linux capabilities. The system.process module should report the capabilities.

go-sysinfo, which this code already uses, supports fetching this data (source), but the returned strings are not in the exact format expected by ECS.

Describe a specific use case for the enhancement or feature:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions