- Notifications
You must be signed in to change notification settings - Fork 25.6k
Fix audit logging to consistently include port number in origin.address #86732
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix audit logging to consistently include port number in origin.address #86732
Conversation
This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes elastic#86694
| Pinging @elastic/es-security (Team:Security) |
| Hi @slobodanadamovic, I've created a changelog YAML for you. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
We document some sample audit events in event-types.asciidoc . Can you please also update the samples docs there to reflect that origin.address now includes the port number alongside the IP address?
Added it in commit: 9cfdb9c @albertzaharovits I've marked this PR to auto-backport this fix to versions v7.17.4, v8.0.2, v8.1.4 and v8.2.1. |
…ss (elastic#86732) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes elastic#86694
💔 Backport failed
You can use sqren/backport to manually backport by running |
…ss (elastic#86732) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes elastic#86694 (cherry picked from commit 954d288) # Conflicts: # x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrail.java # x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrailService.java
💚 All backports created successfully
Questions ?Please refer to the Backport tool documentation |
…ss (#86732) (#86969) This commit changes audit logging of `connection_denied` and `connection_granted` events in order to include a port number. Closes #86694 (cherry picked from commit 954d288) # Conflicts: # x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrail.java # x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/audit/AuditTrailService.java
This PR changes audit logging of
connection_deniedand
connection_grantedevents in order to include a port number.Closes #86694