Repository navigation
[system] Use user.target.* in New users and groups dashboard - #20352
Conversation
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
🚀 Benchmarks reportPackage
|
| Data stream | Previous EPS | New EPS | Diff (%) | Result |
|---|---|---|---|---|
security |
1567.4 | 1195.03 | -372.37 (-23.76%) | 💔 |
auth |
5000 | 2695.42 | -2304.58 (-46.09%) | 💔 |
To see the full report comment with /test benchmark fullreport
|
/test benchmark fullreport |
c9013d4 to
22ed856
Compare
There was a problem hiding this comment.
Pull request overview
Updates the System integration’s “[Logs System] New users and groups” Kibana dashboard to use ECS user.target.* fields for created accounts (useradd events), aligning the dashboard with the expand-and-contract migration away from the deprecated user.* duplication.
Changes:
- Bump the System package version to
2.23.0. - Update the “New users” Lens panels in the dashboard to read
user.target.name/user.target.idinstead ofuser.name/user.id. - Add a changelog entry documenting the dashboard field switch and the
2.22.0+event requirement.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| packages/system/manifest.yml | Bumps package version to 2.23.0. |
| packages/system/kibana/dashboard/system-0d3f2380-fa78-11e6-ae9b-81e5311e8cab.json | Switches “New users” panels to user.target.* fields. |
| packages/system/changelog.yml | Documents the dashboard update and notes the 2.22.0+ ingestion constraint. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
Updates the "[Logs System] New users and groups" dashboard to read the created account from user.target.name/user.target.id instead of user.name/user.id in the four New users panels (table, over time, by shell, by home directory). The New groups panels are unchanged, as groupadd events still map group.name/group.id. Since system 2.22.0 (#20339) useradd events populate user.target.* with the created account; user.name/user.id only carry a deprecated duplication that a future major version will remove (contract phase of the expand-and-contract migration, #20105). Moving the dashboard to the new fields now means it keeps working after that removal. Note the New users panels only show events ingested with system 2.22.0 or later, where user.target.* was introduced for useradd events.
b21d76b to
d3aec31
Compare
|
✅ All changelog entries have the correct PR link. |
💚 Build Succeeded
History
|
iblancof
left a comment
There was a problem hiding this comment.
One thing worth considering: users who upgrade but have pre-2.22.0 data will see the New Users panels go blank with no error explaining why.
The changelog already flags it:
The New users panels only show events ingested with system 2.22.0 or later, where these fields were introduced.
That covers people who read the changelog, but I wonder if users who see empty panels would connect it to the upgrade. Not sure if this is the kind of thing that has caused friction before, but if it has, a short KB article covering what changed and what to do about it might be worth having.
|
@iblancof good point about the empty panels. Follow-up in #21311: a Troubleshooting entry in the System README (which surfaces on the integration's Overview tab in Kibana) explaining why the New users panels are empty for pre-2.22.0 data, plus an |
…M events (#20353) Mechanically this deletes the five *_compat processors that 2.22.0 introduced for backward compatibility; for existing fixture lines the regenerated pipeline test expectations differ only by the removal of the duplicated fields. It also replaces set_user_target_name_chauthtok (which copied user.name into user.target.name) with renames that route the account parsed from non-success passwd:chauthtok messages (the user= of an authentication failure, or the quoted user of the "does not exist" message) straight to user.target.name, the same way the successful "password changed for" case already works. A user.name populated upstream is left untouched, and chauthtok accounts are excluded from the generic renames into user.name. New fixture lines cover both messages, and a new fixture with a pre-populated user.name covers all three chauthtok paths. Ships as 3.0.0 with a breaking-change changelog entry, which Kibana shows for acknowledgment on UI-initiated upgrades. The bundled New users and groups dashboard already reads user.target.* as of 2.24.0 (#20352).
Proposed commit message
Updates the "[Logs System] New users and groups" dashboard to read the
created account from
user.target.name/user.target.idinstead ofuser.name/user.idin the four New users panels (table, over time, byshell, by home directory). The New groups panels are unchanged, as groupadd
events still map
group.name/group.id.Since system 2.22.0 (#20339) useradd events populate
user.target.*with the created account;user.name/user.idonly carry adeprecated duplication that a future major version will remove (contract
phase of the expand-and-contract migration, #20105).
Moving the dashboard to the new fields now means it keeps working after that
removal.
Note the New users panels only show events ingested with system 2.22.0 or
later, where
user.target.*was introduced for useradd events.Checklist
I have verified that all data streams collect metrics or logs.N/A, dashboard-only changechangelog.ymlfile.I have verified that Kibana version constraints are current according to guidelines.N/A, no new field types or features usedAuthor's Checklist
events ingested with system 2.22.0+; older useradd events will no longer
appear in them. This is disclosed in the changelog entry.
How to test this PR locally
Then in Kibana:
system auth logfile stream (or POST a doc through the
logs-system.auth-2.24.0pipeline intologs-system.auth-default):Jul 24 12:00:00 testhost useradd[1234]: new user: name=alice, UID=1001, GID=1001, home=/home/alice, shell=/bin/bashNew users table shows the account with User=alice and UID=1001, and the
over time / by shell / by home directory panels populate.
Related issues