diff --git a/CHANGELOG.next.asciidoc b/CHANGELOG.next.asciidoc index 3135d2966f10..87ac6c8e0ed9 100644 --- a/CHANGELOG.next.asciidoc +++ b/CHANGELOG.next.asciidoc @@ -196,6 +196,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d - Metricbeat no longer needs to be started strictly after Logstash for `logstash-xpack` module to report correct data. {issue}17261[17261] {pull}17497[17497] - Add privileged option so as mb to access data dir in Openshift. {pull}17606[17606] - Fix "ID" event generator of Google Cloud module {issue}17160[17160] {pull}17608[17608] +- Add privileged option for Auditbeat in Openshift {pull}17637[17637] - Fix storage metricset to allow config without region/zone. {issue}17623[17623] {pull}17624[17624] *Packetbeat* diff --git a/deploy/kubernetes/auditbeat-kubernetes.yaml b/deploy/kubernetes/auditbeat-kubernetes.yaml index dd0727d7444b..1b2abec791b1 100644 --- a/deploy/kubernetes/auditbeat-kubernetes.yaml +++ b/deploy/kubernetes/auditbeat-kubernetes.yaml @@ -133,6 +133,8 @@ spec: fieldPath: spec.nodeName securityContext: runAsUser: 0 + # If using Red Hat OpenShift uncomment this: + #privileged: true capabilities: add: # Capabilities needed for auditd module diff --git a/deploy/kubernetes/auditbeat/auditbeat-daemonset.yaml b/deploy/kubernetes/auditbeat/auditbeat-daemonset.yaml index 79a4c473da7b..21ffb167107a 100644 --- a/deploy/kubernetes/auditbeat/auditbeat-daemonset.yaml +++ b/deploy/kubernetes/auditbeat/auditbeat-daemonset.yaml @@ -46,6 +46,8 @@ spec: fieldPath: spec.nodeName securityContext: runAsUser: 0 + # If using Red Hat OpenShift uncomment this: + #privileged: true capabilities: add: # Capabilities needed for auditd module