Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

googlecloud/vpcflow fileset: Populate additional log fields #14608

Merged
merged 2 commits into from
Nov 20, 2019

Conversation

adriansr
Copy link
Contributor

To keep the vpcflow fileset of the googlecloud module aligned with the new firewall fileset, a var.keep_original_message option is added. Also the log.logger ECS field is now filled.

@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

To keep the vpcflow fileset of the googlecloud module aligned with the
new firewall fileset, a `var.keep_original_message` option is added.
Also the log.logger ECS field is now filled.
@adriansr adriansr merged commit e71570a into elastic:master Nov 20, 2019
adriansr added a commit to adriansr/beats that referenced this pull request Jan 16, 2020
…14608)

To keep the vpcflow fileset of the googlecloud module aligned with the
new firewall fileset, a `var.keep_original_message` option is added.
Also the log.logger ECS field is now filled.
adriansr added a commit that referenced this pull request Jan 17, 2020
…15621)

* New fileset for googlecloud firewall logs (#14553)

This PR adds a new fileset, firewall, to the googlecloud module in Filebeat. It helps
parsing firewall logs generated by rules under VPC Network -> Firewall Rules.

Note that GCP only logs firewall events under the following conditions:
- Logging needs to be enabled for each individual rule in order to log.
- Only TCP and UDP rules can be logged.

(cherry picked from commit 4a66f0b)

* googlecloud/vpcflow fileset: Populate additional log fields (#14608)

To keep the vpcflow fileset of the googlecloud module aligned with the
new firewall fileset, a `var.keep_original_message` option is added.
Also the log.logger ECS field is now filled.
adriansr added a commit to adriansr/beats that referenced this pull request Jan 17, 2020
…l logs (elastic#15621)

* New fileset for googlecloud firewall logs (elastic#14553)

This PR adds a new fileset, firewall, to the googlecloud module in Filebeat. It helps
parsing firewall logs generated by rules under VPC Network -> Firewall Rules.

Note that GCP only logs firewall events under the following conditions:
- Logging needs to be enabled for each individual rule in order to log.
- Only TCP and UDP rules can be logged.

(cherry picked from commit 4a66f0b)

* googlecloud/vpcflow fileset: Populate additional log fields (elastic#14608)

To keep the vpcflow fileset of the googlecloud module aligned with the
new firewall fileset, a `var.keep_original_message` option is added.
Also the log.logger ECS field is now filled.

(cherry picked from commit 22fb66d)
adriansr added a commit that referenced this pull request Jan 17, 2020
…15621) (#15625)

* New fileset for googlecloud firewall logs (#14553)

This PR adds a new fileset, firewall, to the googlecloud module in Filebeat. It helps
parsing firewall logs generated by rules under VPC Network -> Firewall Rules.

Note that GCP only logs firewall events under the following conditions:
- Logging needs to be enabled for each individual rule in order to log.
- Only TCP and UDP rules can be logged.

(cherry picked from commit 4a66f0b)

* googlecloud/vpcflow fileset: Populate additional log fields (#14608)

To keep the vpcflow fileset of the googlecloud module aligned with the
new firewall fileset, a `var.keep_original_message` option is added.
Also the log.logger ECS field is now filled.

(cherry picked from commit 22fb66d)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants