Skip to content

[system] Use user.target.* in New users and groups dashboard - #20352

Merged
nicholasberlin merged 1 commit into
mainfrom
fix/system-new-users-dashboard-user-target
Sep 15, 2026
Merged

nicholasberlin merged 1 commit into
mainfrom
fix/system-new-users-dashboard-user-target

Conversation

@nicholasberlin

@nicholasberlin nicholasberlin commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

Proposed commit message

Updates the "[Logs System] New users and groups" dashboard to read the
created account from user.target.name/user.target.id instead of
user.name/user.id in the four New users panels (table, over time, by
shell, by home directory). The New groups panels are unchanged, as groupadd
events still map group.name/group.id.

Since system 2.22.0 (#20339) useradd events populate
user.target.* with the created account; user.name/user.id only carry a
deprecated duplication that a future major version will remove (contract
phase of the expand-and-contract migration, #20105).
Moving the dashboard to the new fields now means it keeps working after that
removal.

Note the New users panels only show events ingested with system 2.22.0 or
later, where user.target.* was introduced for useradd events.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs. N/A, dashboard-only change
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines. N/A, no new field types or features used
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • The New users panels intentionally switch to fields that only exist on
    events ingested with system 2.22.0+; older useradd events will no longer
    appear in them. This is disclosed in the changelog entry.

How to test this PR locally

cd packages/system
elastic-package stack up -d
elastic-package build && elastic-package install

Then in Kibana:

  1. Ingest a useradd auth event, e.g. append to a file collected by the
    system auth logfile stream (or POST a doc through the
    logs-system.auth-2.24.0 pipeline into logs-system.auth-default):
    Jul 24 12:00:00 testhost useradd[1234]: new user: name=alice, UID=1001, GID=1001, home=/home/alice, shell=/bin/bash
  2. Open the "[Logs System] New users and groups" dashboard and verify the
    New users table shows the account with User=alice and UID=1001, and the
    over time / by shell / by home directory panels populate.
  3. Verify the New groups panels still work for a groupadd event.

Related issues

@nicholasberlin
nicholasberlin requested review from a team as code owners July 24, 2026 17:29
@nicholasberlin nicholasberlin added Integration:system System bugfix Pull request that fixes a bug issue Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform] labels Jul 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

Package system 👍(1) 💚(1) 💔(2)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
security 1567.4 1195.03 -372.37 (-23.76%) 💔
auth 5000 2695.42 -2304.58 (-46.09%) 💔

To see the full report comment with /test benchmark fullreport

@nicholasberlin

Copy link
Copy Markdown
Contributor Author

/test benchmark fullreport

@andrewkroh andrewkroh added dashboard Relates to a Kibana dashboard bug, enhancement, or modification. Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] labels Jul 24, 2026
@nicholasberlin
nicholasberlin force-pushed the fix/system-new-users-dashboard-user-target branch 2 times, most recently from c9013d4 to 22ed856 Compare August 3, 2026 15:46
@nicholasberlin
nicholasberlin enabled auto-merge (squash) August 3, 2026 16:04
Copilot AI lite review requested due to automatic review settings August 13, 2026 13:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the System integration’s “[Logs System] New users and groups” Kibana dashboard to use ECS user.target.* fields for created accounts (useradd events), aligning the dashboard with the expand-and-contract migration away from the deprecated user.* duplication.

Changes:

  • Bump the System package version to 2.23.0.
  • Update the “New users” Lens panels in the dashboard to read user.target.name / user.target.id instead of user.name / user.id.
  • Add a changelog entry documenting the dashboard field switch and the 2.22.0+ event requirement.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
packages/system/manifest.yml Bumps package version to 2.23.0.
packages/system/kibana/dashboard/system-0d3f2380-fa78-11e6-ae9b-81e5311e8cab.json Switches “New users” panels to user.target.* fields.
packages/system/changelog.yml Documents the dashboard update and notes the 2.22.0+ ingestion constraint.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@botelastic

botelastic Bot commented Sep 12, 2026

Copy link
Copy Markdown

Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

@botelastic botelastic Bot added the Stalled label Sep 12, 2026
@botelastic botelastic Bot removed the Stalled label Sep 14, 2026
@chrisberkhout
chrisberkhout requested review from a team as code owners September 14, 2026 12:28
Copilot AI review requested due to automatic review settings September 14, 2026 12:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review is ineligible. To be eligible to request a review, you need a paid Copilot license, or your organization must enable Copilot code review.

Updates the "[Logs System] New users and groups" dashboard to read the
created account from user.target.name/user.target.id instead of
user.name/user.id in the four New users panels (table, over time, by
shell, by home directory). The New groups panels are unchanged, as
groupadd events still map group.name/group.id.

Since system 2.22.0 (#20339) useradd events populate
user.target.* with the created account; user.name/user.id only carry a
deprecated duplication that a future major version will remove
(contract phase of the expand-and-contract migration,
#20105). Moving the dashboard to the new fields now
means it keeps working after that removal.

Note the New users panels only show events ingested with system 2.22.0
or later, where user.target.* was introduced for useradd events.
@nicholasberlin
nicholasberlin force-pushed the fix/system-new-users-dashboard-user-target branch from b21d76b to d3aec31 Compare September 14, 2026 16:28
Copilot AI review requested due to automatic review settings September 14, 2026 16:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved blocking issues remain.

Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

@iblancof iblancof left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One thing worth considering: users who upgrade but have pre-2.22.0 data will see the New Users panels go blank with no error explaining why.

The changelog already flags it:

The New users panels only show events ingested with system 2.22.0 or later, where these fields were introduced.

That covers people who read the changelog, but I wonder if users who see empty panels would connect it to the upgrade. Not sure if this is the kind of thing that has caused friction before, but if it has, a short KB article covering what changed and what to do about it might be worth having.

@nicholasberlin
nicholasberlin merged commit 8b82b93 into main Sep 15, 2026
11 checks passed
@nicholasberlin
nicholasberlin deleted the fix/system-new-users-dashboard-user-target branch September 15, 2026 06:22
@nicholasberlin

Copy link
Copy Markdown
Contributor Author

@iblancof good point about the empty panels. Follow-up in #21311: a Troubleshooting entry in the System README (which surfaces on the integration's Overview tab in Kibana) explaining why the New users panels are empty for pre-2.22.0 data, plus an _update_by_query to backfill user.target.name/user.target.id from user.name/user.id on historical useradd events. That also gives Support a linkable source if a KB article turns out to be warranted.

chrisberkhout pushed a commit that referenced this pull request Sep 27, 2026
…M events (#20353)

Mechanically this deletes the five *_compat processors that 2.22.0
introduced for backward compatibility; for existing fixture lines the
regenerated pipeline test expectations differ only by the removal of the
duplicated fields. It also replaces set_user_target_name_chauthtok (which
copied user.name into user.target.name) with renames that route the account
parsed from non-success passwd:chauthtok messages (the user= of an
authentication failure, or the quoted user of the "does not exist" message)
straight to user.target.name, the same way the successful "password changed
for" case already works. A user.name populated upstream is left untouched,
and chauthtok accounts are excluded from the generic renames into user.name.
New fixture lines cover both messages, and a new fixture with a
pre-populated user.name covers all three chauthtok paths.

Ships as 3.0.0 with a breaking-change changelog entry, which Kibana shows
for acknowledgment on UI-initiated upgrades. The bundled New users and
groups dashboard already reads user.target.* as of 2.24.0 (#20352).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue dashboard Relates to a Kibana dashboard bug, enhancement, or modification. Integration:system System Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants