diff --git a/CHANGELOG.next.md b/CHANGELOG.next.md index c9bebd73c..b527829e8 100644 --- a/CHANGELOG.next.md +++ b/CHANGELOG.next.md @@ -15,6 +15,7 @@ Thanks, you're awesome :-) --> #### Bugfixes #### Added +* Added `container.privileged` to indicated whether a container was started in privileged mode. #2219 #### Improvements diff --git a/docs/fields/field-details.asciidoc b/docs/fields/field-details.asciidoc index 28d6f700f..80ec002df 100644 --- a/docs/fields/field-details.asciidoc +++ b/docs/fields/field-details.asciidoc @@ -1213,6 +1213,22 @@ type: long +| extended + +// =============================================================== + +| +[[field-container-privileged]] +<> + +a| Indicates whether the container is running in privileged mode. + +type: bool + + + + + | extended // =============================================================== diff --git a/experimental/generated/beats/fields.ecs.yml b/experimental/generated/beats/fields.ecs.yml index b7b136082..8ff00d698 100644 --- a/experimental/generated/beats/fields.ecs.yml +++ b/experimental/generated/beats/fields.ecs.yml @@ -944,6 +944,11 @@ description: The number of bytes received (gauge) on all network interfaces by the container since the last metric collection. default_field: false + - name: privileged + level: extended + type: bool + description: Indicates whether the container is running in privileged mode. + default_field: false - name: runtime level: extended type: keyword diff --git a/experimental/generated/csv/fields.csv b/experimental/generated/csv/fields.csv index 810c86fbb..2d62bf691 100644 --- a/experimental/generated/csv/fields.csv +++ b/experimental/generated/csv/fields.csv @@ -99,6 +99,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Normalization,Example,Description 8.10.0-dev+exp,true,container,container.name,keyword,extended,,,Container name. 8.10.0-dev+exp,true,container,container.network.egress.bytes,long,extended,,,The number of bytes sent on all network interfaces. 8.10.0-dev+exp,true,container,container.network.ingress.bytes,long,extended,,,The number of bytes received on all network interfaces. +8.10.0-dev+exp,true,container,container.privileged,bool,extended,,,Indicates whether the container is running in privileged mode. 8.10.0-dev+exp,true,container,container.runtime,keyword,extended,,docker,Runtime managing this container. 8.10.0-dev+exp,true,data_stream,data_stream.dataset,constant_keyword,extended,,nginx.access,The field can contain anything that makes sense to signify the source of the data. 8.10.0-dev+exp,true,data_stream,data_stream.namespace,constant_keyword,extended,,production,A user defined namespace. Namespaces are useful to allow grouping of data. diff --git a/experimental/generated/ecs/ecs_flat.yml b/experimental/generated/ecs/ecs_flat.yml index 8a9b92abe..af895f4dd 100644 --- a/experimental/generated/ecs/ecs_flat.yml +++ b/experimental/generated/ecs/ecs_flat.yml @@ -1183,6 +1183,15 @@ container.network.ingress.bytes: normalize: [] short: The number of bytes received on all network interfaces. type: long +container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/experimental/generated/ecs/ecs_nested.yml b/experimental/generated/ecs/ecs_nested.yml index 0847697c3..9cabccb95 100644 --- a/experimental/generated/ecs/ecs_nested.yml +++ b/experimental/generated/ecs/ecs_nested.yml @@ -1562,6 +1562,15 @@ container: normalize: [] short: The number of bytes received on all network interfaces. type: long + container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/experimental/generated/elasticsearch/composable/component/container.json b/experimental/generated/elasticsearch/composable/component/container.json index 61b9d3fb5..fa7a0421e 100644 --- a/experimental/generated/elasticsearch/composable/component/container.json +++ b/experimental/generated/elasticsearch/composable/component/container.json @@ -91,6 +91,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/experimental/generated/elasticsearch/legacy/template.json b/experimental/generated/elasticsearch/legacy/template.json index e04671d80..fa866c025 100644 --- a/experimental/generated/elasticsearch/legacy/template.json +++ b/experimental/generated/elasticsearch/legacy/template.json @@ -560,6 +560,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/generated/beats/fields.ecs.yml b/generated/beats/fields.ecs.yml index 1c99c802b..958e7d5b0 100644 --- a/generated/beats/fields.ecs.yml +++ b/generated/beats/fields.ecs.yml @@ -894,6 +894,11 @@ description: The number of bytes received (gauge) on all network interfaces by the container since the last metric collection. default_field: false + - name: privileged + level: extended + type: bool + description: Indicates whether the container is running in privileged mode. + default_field: false - name: runtime level: extended type: keyword diff --git a/generated/csv/fields.csv b/generated/csv/fields.csv index 4ccb5f6a1..6d53d2829 100644 --- a/generated/csv/fields.csv +++ b/generated/csv/fields.csv @@ -92,6 +92,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Normalization,Example,Description 8.10.0-dev,true,container,container.name,keyword,extended,,,Container name. 8.10.0-dev,true,container,container.network.egress.bytes,long,extended,,,The number of bytes sent on all network interfaces. 8.10.0-dev,true,container,container.network.ingress.bytes,long,extended,,,The number of bytes received on all network interfaces. +8.10.0-dev,true,container,container.privileged,bool,extended,,,Indicates whether the container is running in privileged mode. 8.10.0-dev,true,container,container.runtime,keyword,extended,,docker,Runtime managing this container. 8.10.0-dev,true,data_stream,data_stream.dataset,constant_keyword,extended,,nginx.access,The field can contain anything that makes sense to signify the source of the data. 8.10.0-dev,true,data_stream,data_stream.namespace,constant_keyword,extended,,production,A user defined namespace. Namespaces are useful to allow grouping of data. diff --git a/generated/ecs/ecs_flat.yml b/generated/ecs/ecs_flat.yml index e042d14ef..f7c3d5695 100644 --- a/generated/ecs/ecs_flat.yml +++ b/generated/ecs/ecs_flat.yml @@ -1114,6 +1114,15 @@ container.network.ingress.bytes: normalize: [] short: The number of bytes received on all network interfaces. type: long +container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/generated/ecs/ecs_nested.yml b/generated/ecs/ecs_nested.yml index eae3f3498..3505dd848 100644 --- a/generated/ecs/ecs_nested.yml +++ b/generated/ecs/ecs_nested.yml @@ -1482,6 +1482,15 @@ container: normalize: [] short: The number of bytes received on all network interfaces. type: long + container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/generated/elasticsearch/composable/component/container.json b/generated/elasticsearch/composable/component/container.json index ae8d22843..a840e22ba 100644 --- a/generated/elasticsearch/composable/component/container.json +++ b/generated/elasticsearch/composable/component/container.json @@ -91,6 +91,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/generated/elasticsearch/legacy/template.json b/generated/elasticsearch/legacy/template.json index 0e0297839..c20ce4dae 100644 --- a/generated/elasticsearch/legacy/template.json +++ b/generated/elasticsearch/legacy/template.json @@ -518,6 +518,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/schemas/container.yml b/schemas/container.yml index b538a4d48..85b888dfc 100644 --- a/schemas/container.yml +++ b/schemas/container.yml @@ -121,6 +121,13 @@ The number of bytes (gauge) sent out on all network interfaces by the container since the last metric collection. + - name: privileged + type: bool + level: extended + short: Indicates whether the container is running in privileged mode. + description: > + Indicates whether the container is running in privileged mode. + - name: runtime level: extended type: keyword