Skip to content

Conversation

@slobodanadamovic
Copy link
Contributor

This PR changes audit logging of connection_denied
and connection_granted events in order to include a port number.

Closes #86694

This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes elastic#86694
@slobodanadamovic slobodanadamovic added >bug :Security/Audit X-Pack Audit logging Team:Security Meta label for security team labels May 12, 2022
@slobodanadamovic slobodanadamovic self-assigned this May 12, 2022
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

@elasticsearchmachine
Copy link
Collaborator

Hi @slobodanadamovic, I've created a changelog YAML for you.

Copy link
Contributor

@albertzaharovits albertzaharovits left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

We document some sample audit events in event-types.asciidoc . Can you please also update the samples docs there to reflect that origin.address now includes the port number alongside the IP address?

@slobodanadamovic
Copy link
Contributor Author

slobodanadamovic commented May 16, 2022

Can you please also update the samples docs there to reflect that origin.address now includes the port number alongside the IP address?

Added it in commit: 9cfdb9c

@albertzaharovits I've marked this PR to auto-backport this fix to versions v7.17.4, v8.0.2, v8.1.4 and v8.2.1.
Do you think this makes sense or should I only do it for affected versions defined in #86694?

@arteam arteam added v7.17.5 and removed v7.17.4 labels May 17, 2022
@slobodanadamovic slobodanadamovic merged commit 954d288 into elastic:master May 20, 2022
slobodanadamovic added a commit to slobodanadamovic/elasticsearch that referenced this pull request May 20, 2022
…ss (elastic#86732) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes elastic#86694
@elasticsearchmachine
Copy link
Collaborator

💔 Backport failed

Status Branch Result
8.2
7.17 Commit could not be cherrypicked due to conflicts

You can use sqren/backport to manually backport by running backport --upstream elastic/elasticsearch --pr 86732

slobodanadamovic added a commit to slobodanadamovic/elasticsearch that referenced this pull request May 20, 2022
…ss (elastic#86732) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes elastic#86694 (cherry picked from commit 954d288) # Conflicts: #	x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrail.java #	x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrailService.java
@slobodanadamovic
Copy link
Contributor Author

💚 All backports created successfully

Status Branch Result
7.17

Questions ?

Please refer to the Backport tool documentation

@slobodanadamovic slobodanadamovic deleted the fix-port-audit-logging branch May 20, 2022 12:03
elasticsearchmachine pushed a commit that referenced this pull request May 20, 2022
…ss (#86732) (#86968) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes #86694
elasticsearchmachine pushed a commit that referenced this pull request May 20, 2022
…ss (#86732) (#86969) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes #86694 (cherry picked from commit 954d288) # Conflicts: #	x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrail.java #	x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrailService.java
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

>bug :Security/Audit X-Pack Audit logging Team:Security Meta label for security team v7.17.5 v8.2.1 v8.3.0

5 participants