-
Notifications
You must be signed in to change notification settings - Fork 24.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
DOC Audit security config change #66839
DOC Audit security config change #66839
Conversation
Co-authored-by: Lisa Cawley <[email protected]>
Co-authored-by: Lisa Cawley <[email protected]>
Thanks for the thorough review Lisa! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added a fix for table formatting and two minor suggestions. Otherwise, LGTM!
x-pack/docs/en/security/auditing/auditing-search-queries.asciidoc
Outdated
Show resolved
Hide resolved
Co-authored-by: Lisa Cawley <[email protected]>
Co-authored-by: Lisa Cawley <[email protected]>
Niice, thank you! |
x-pack/docs/en/security/auditing/auditing-search-queries.asciidoc
Outdated
Show resolved
Hide resolved
|
||
| `put_user` | ||
| Logged when the <<security-api-put-user,put user API>> is invoked to create or | ||
update a native or built-in user. Note that user updates can also change the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
update a native or built-in user. Note that user updates can also change the | |
update a native user. Note that user updates can also change the |
You cannot call the put user API on a reserved user.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ha! yeah, that's right. I think I remember looking specifically about that, but I must've not looked in the transport action for the validation.
Though, technically, the put_user
event will be emitted for reserved users too, because auditing happens before validation.
But I'll go with your suggestion.
Co-authored-by: Tim Vernum <[email protected]>
Co-authored-by: Tim Vernum <[email protected]>
Co-authored-by: Tim Vernum <[email protected]>
Co-authored-by: Tim Vernum <[email protected]>
Co-authored-by: Tim Vernum <[email protected]>
@elasticmachine run elasticsearch-ci/packaging-sample-unix |
Audit log doc changes about: * the new security_config_change event type (main scope of this PR) * remove mentions of the 6.5 audit format changes (the JSON format) * mention the new archiving and rotation by size (in v8 only) * mention the request.id event attribute used to correlate audit events * mention that audit is only available on certain subscription levels * add an exhaustive audit event example list (because schema became too complex to explain in words 😢 given the new security_config_change events) * move the ignore policies are explained on a separate page (it was collocated with the logfile output since we had multiple outputs and the policies were specific the the logfile only). Co-authored-by: Lisa Cawley [email protected] Relates elastic#62916 Closes elastic#29912
Audit log doc changes about: * the new security_config_change event type (main scope of this PR) * remove mentions of the 6.5 audit format changes (the JSON format) * mention the new archiving and rotation by size (in v8 only) * mention the request.id event attribute used to correlate audit events * mention that audit is only available on certain subscription levels * add an exhaustive audit event example list (because schema became too complex to explain in words 😢 given the new security_config_change events) * move the ignore policies are explained on a separate page (it was collocated with the logfile output since we had multiple outputs and the policies were specific the the logfile only). Co-authored-by: Lisa Cawley [email protected] Relates #62916 Closes #29912
Audit log doc changes about:
security_config_change
event type (main scope of this PR)request.id
event attribute used to correlate audit eventssecurity_config_change
events)logfile
only).Relates #62916 .
Closes #29912 .
Co-authored-by: Lisa Cawley [email protected]
Preview