diff --git a/docs/fields/field-details.asciidoc b/docs/fields/field-details.asciidoc index 28d6f700f0..80ec002df7 100644 --- a/docs/fields/field-details.asciidoc +++ b/docs/fields/field-details.asciidoc @@ -1213,6 +1213,22 @@ type: long +| extended + +// =============================================================== + +| +[[field-container-privileged]] +<> + +a| Indicates whether the container is running in privileged mode. + +type: bool + + + + + | extended // =============================================================== diff --git a/experimental/generated/beats/fields.ecs.yml b/experimental/generated/beats/fields.ecs.yml index 5024360172..bd212db7c9 100644 --- a/experimental/generated/beats/fields.ecs.yml +++ b/experimental/generated/beats/fields.ecs.yml @@ -944,6 +944,11 @@ description: The number of bytes received (gauge) on all network interfaces by the container since the last metric collection. default_field: false + - name: privileged + level: extended + type: bool + description: Indicates whether the container is running in privileged mode. + default_field: false - name: runtime level: extended type: keyword diff --git a/experimental/generated/csv/fields.csv b/experimental/generated/csv/fields.csv index 02bc6b6793..b096ad0804 100644 --- a/experimental/generated/csv/fields.csv +++ b/experimental/generated/csv/fields.csv @@ -99,6 +99,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Normalization,Example,Description 8.9.0-dev+exp,true,container,container.name,keyword,extended,,,Container name. 8.9.0-dev+exp,true,container,container.network.egress.bytes,long,extended,,,The number of bytes sent on all network interfaces. 8.9.0-dev+exp,true,container,container.network.ingress.bytes,long,extended,,,The number of bytes received on all network interfaces. +8.9.0-dev+exp,true,container,container.privileged,bool,extended,,,Indicates whether the container is running in privileged mode. 8.9.0-dev+exp,true,container,container.runtime,keyword,extended,,docker,Runtime managing this container. 8.9.0-dev+exp,true,data_stream,data_stream.dataset,constant_keyword,extended,,nginx.access,The field can contain anything that makes sense to signify the source of the data. 8.9.0-dev+exp,true,data_stream,data_stream.namespace,constant_keyword,extended,,production,A user defined namespace. Namespaces are useful to allow grouping of data. diff --git a/experimental/generated/ecs/ecs_flat.yml b/experimental/generated/ecs/ecs_flat.yml index 8a9b92abef..af895f4dd2 100644 --- a/experimental/generated/ecs/ecs_flat.yml +++ b/experimental/generated/ecs/ecs_flat.yml @@ -1183,6 +1183,15 @@ container.network.ingress.bytes: normalize: [] short: The number of bytes received on all network interfaces. type: long +container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/experimental/generated/ecs/ecs_nested.yml b/experimental/generated/ecs/ecs_nested.yml index 0847697c3b..9cabccb95a 100644 --- a/experimental/generated/ecs/ecs_nested.yml +++ b/experimental/generated/ecs/ecs_nested.yml @@ -1562,6 +1562,15 @@ container: normalize: [] short: The number of bytes received on all network interfaces. type: long + container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/experimental/generated/elasticsearch/composable/component/container.json b/experimental/generated/elasticsearch/composable/component/container.json index 0ac4eac808..8fcda572aa 100644 --- a/experimental/generated/elasticsearch/composable/component/container.json +++ b/experimental/generated/elasticsearch/composable/component/container.json @@ -91,6 +91,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/experimental/generated/elasticsearch/legacy/template.json b/experimental/generated/elasticsearch/legacy/template.json index eea9f65645..d309530cf6 100644 --- a/experimental/generated/elasticsearch/legacy/template.json +++ b/experimental/generated/elasticsearch/legacy/template.json @@ -560,6 +560,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/generated/beats/fields.ecs.yml b/generated/beats/fields.ecs.yml index 4874bbb2aa..421d885a5a 100644 --- a/generated/beats/fields.ecs.yml +++ b/generated/beats/fields.ecs.yml @@ -894,6 +894,11 @@ description: The number of bytes received (gauge) on all network interfaces by the container since the last metric collection. default_field: false + - name: privileged + level: extended + type: bool + description: Indicates whether the container is running in privileged mode. + default_field: false - name: runtime level: extended type: keyword diff --git a/generated/csv/fields.csv b/generated/csv/fields.csv index 82a0b4ddc5..c7f91c63a0 100644 --- a/generated/csv/fields.csv +++ b/generated/csv/fields.csv @@ -92,6 +92,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Normalization,Example,Description 8.9.0-dev,true,container,container.name,keyword,extended,,,Container name. 8.9.0-dev,true,container,container.network.egress.bytes,long,extended,,,The number of bytes sent on all network interfaces. 8.9.0-dev,true,container,container.network.ingress.bytes,long,extended,,,The number of bytes received on all network interfaces. +8.9.0-dev,true,container,container.privileged,bool,extended,,,Indicates whether the container is running in privileged mode. 8.9.0-dev,true,container,container.runtime,keyword,extended,,docker,Runtime managing this container. 8.9.0-dev,true,data_stream,data_stream.dataset,constant_keyword,extended,,nginx.access,The field can contain anything that makes sense to signify the source of the data. 8.9.0-dev,true,data_stream,data_stream.namespace,constant_keyword,extended,,production,A user defined namespace. Namespaces are useful to allow grouping of data. diff --git a/generated/ecs/ecs_flat.yml b/generated/ecs/ecs_flat.yml index e042d14ef4..f7c3d56957 100644 --- a/generated/ecs/ecs_flat.yml +++ b/generated/ecs/ecs_flat.yml @@ -1114,6 +1114,15 @@ container.network.ingress.bytes: normalize: [] short: The number of bytes received on all network interfaces. type: long +container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/generated/ecs/ecs_nested.yml b/generated/ecs/ecs_nested.yml index eae3f3498d..3505dd848e 100644 --- a/generated/ecs/ecs_nested.yml +++ b/generated/ecs/ecs_nested.yml @@ -1482,6 +1482,15 @@ container: normalize: [] short: The number of bytes received on all network interfaces. type: long + container.privileged: + dashed_name: container-privileged + description: Indicates whether the container is running in privileged mode. + flat_name: container.privileged + level: extended + name: privileged + normalize: [] + short: Indicates whether the container is running in privileged mode. + type: bool container.runtime: dashed_name: container-runtime description: Runtime managing this container. diff --git a/generated/elasticsearch/composable/component/container.json b/generated/elasticsearch/composable/component/container.json index 234aa5763a..abe0090990 100644 --- a/generated/elasticsearch/composable/component/container.json +++ b/generated/elasticsearch/composable/component/container.json @@ -91,6 +91,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword" diff --git a/generated/elasticsearch/legacy/template.json b/generated/elasticsearch/legacy/template.json index bd747c0c7d..096e4eb18c 100644 --- a/generated/elasticsearch/legacy/template.json +++ b/generated/elasticsearch/legacy/template.json @@ -518,6 +518,9 @@ } } }, + "privileged": { + "type": "bool" + }, "runtime": { "ignore_above": 1024, "type": "keyword"