Repository navigation
[system][auth] Remove deprecated user.name/user.id duplication for IAM events - #20353
Conversation
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
a0ff7c3 to
6b7ceb9
Compare
|
The deprecation release was here: #20105 (comment) July 24, 2026 Not sure how long of a grace period. |
🚀 Benchmarks reportTo see the full report comment with |
|
The deprecation release was here: #20105 (comment) July 24, 2026 Not sure how long of a grace period. |
23bcd0d to
40db538
Compare
There was a problem hiding this comment.
Pull request overview
This PR implements the contract phase of the System auth ingest pipeline’s expand/contract migration by removing the deprecated duplication of affected-account fields into user.name/user.id for IAM events, aligning emitted documents with ECS semantics (actor in user.*, affected account in user.target.*).
Changes:
- Removes the
*_compatprocessors that duplicateduser.target.*intouser.name/user.idfor useradd/usermod/userdel/PAM chauthtok IAM events. - Bumps the System package version to 3.0.0 and adds a breaking-change changelog entry describing the field behavior change.
- Regenerates pipeline test expected outputs to reflect the removal of duplicated
user.name/user.id(including journald cases whereuser.idis no longer overwritten).
Reviewed changes
Copilot reviewed 12 out of 12 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| packages/system/manifest.yml | Bumps package version to 3.0.0 for the breaking change. |
| packages/system/data_stream/auth/elasticsearch/ingest_pipeline/message.yml | Removes backward-compat field duplication processors for IAM events. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-usermod-group.log-expected.json | Updates expectations to no longer include duplicated user.name for usermod group changes. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-userdel.log-expected.json | Updates expectations to no longer include duplicated user.name for userdel events. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-pam-extraction.log-expected.json | Updates expectations to no longer duplicate PAM target user into user.name. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-pam-chauthtok-iso8601.log-expected.json | Updates ISO8601 PAM chauthtok expectations to remove user.name duplication. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-auth.log-expected.json | Updates baseline auth fixture expectations to remove useradd user.name/user.id duplication. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-auth-ubuntu1204.log-expected.json | Updates Ubuntu fixture expectations to remove duplicated user.* fields on IAM events. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-auth-rhel79.log-expected.json | Updates RHEL fixture expectations to remove duplicated user.name on IAM events. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-auth-debian11.json-expected.json | Updates journald fixture expectations to stop overwriting user.id with the created account’s UID and remove user.name duplication. |
| packages/system/data_stream/auth/_dev/test/pipeline/test-auth-debian11-preserve-original.json-expected.json | Same as above for the preserve-original variant. |
| packages/system/changelog.yml | Adds 3.0.0 breaking-change entry documenting the removal of duplicated fields. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
Updates the "[Logs System] New users and groups" dashboard to read the created account from user.target.name/user.target.id instead of user.name/user.id in the four New users panels (table, over time, by shell, by home directory). The New groups panels are unchanged, as groupadd events still map group.name/group.id. Since system 2.22.0 (#20339) useradd events populate user.target.* with the created account; user.name/user.id only carry a deprecated duplication that a future major version will remove (contract phase of the expand-and-contract migration, #20105). Moving the dashboard to the new fields now means it keeps working after that removal. Note the New users panels only show events ingested with system 2.22.0 or later, where user.target.* was introduced for useradd events.
479ef39 to
108f265
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The PAM rename may overwrite actor identity by moving pre-existing user.name into user.target.name.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
….name Instead of moving whatever is in user.name into user.target.name for chauthtok events, rename the parser-populated _temp.pam_user (the user= field of an authentication failure) and _temp.user (quoted user in the debug-level "does not exist" message) directly to user.target.name, mirroring how _temp.pam_target is handled. A user.name populated upstream (for example by an agent processor) is left alone, and rename_pam_target can no longer be blocked by a wrongly copied actor. No fixture changes: the parsed account lands in user.target.name either way.
|
@chrisberkhout small follow-up to the chauthtok change: Copilot pointed out that renaming |
If user.target.name is already populated when a chauthtok event arrives, the chauthtok-specific renames skip and _temp.pam_user/_temp.user would fall through to the generic renames into user.name. Exclude chauthtok from those so the parsed account is dropped rather than misattributed. Add the debug-level pam_unix 'user "x" does not exist in /etc/passwd' message to the chauthtok fixture to cover the _temp.user path.
|
Follow-ups from the latest bot passes, in af50455:
As before, the new expected entry is hand-derived; CI will confirm. |
|
🟢 No issues across the latest commits af50455. Review summaryIssues found across earlier commits 69fe93b — 1 lowPackage-level:
Issues found across earlier commits 987c7d1…108f265 (229 commits) — 1 low
🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills
|
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
|
✅ All changelog entries have the correct PR link. |
💚 Build Succeeded
History
|
|
Package system - 3.0.0 containing this change is available at https://epr.elastic.co/package/system/3.0.0/ |

Proposed commit message (updated)
Original proposed commit message
Contract phase of the expand-and-contract migration started in 2.22.0
(#20339): the auth data stream no longer writes the
affected account to
user.name/user.idfor useradd account creation,usermod account changes (for example group membership or expiration changes),
userdel deletion, and PAM password change events. The affected account remains
in
user.target.name(anduser.target.idfor useradd);user.nameon theseevents is reserved for the acting user, matching ECS semantics. On journald
input, useradd events now keep the actor UID from journald metadata in
user.idinstead of having it overwritten by the created account's UID.Mechanically this deletes the five
*_compatprocessors that 2.22.0introduced for backward compatibility and regenerates the pipeline test
expectations, whose diff is exactly the removal of the duplicated fields. It
also replaces
set_user_target_name_chauthtok(which copieduser.nameintouser.target.name) with renames that route the account parsed fromnon-success
passwd:chauthtokmessages (theuser=of anauthentication failure, or the quoted user of the debug-leveldoes not existmessage) straight touser.target.name, the same way thesuccessful
password changed forcase already works. Auser.namepopulatedupstream is left untouched, and chauthtok accounts are excluded from the
generic renames into
user.name. Fixture lines cover both messages.Ships as 3.0.0 with a breaking-change changelog entry so Kibana requires
users to acknowledge the change before upgrading. The bundled New users and
groups dashboard already reads
user.target.*as of 2.24.0 (#20352).Checklist
I have verified that all data streams collect metrics or logs.N/A, pipeline-only changechangelog.ymlfile.I have verified that Kibana version constraints are current according to guidelines.N/AI have verified that any added dashboard complies with Kibana's Dashboard good practicesN/AAuthor's Checklist
to date with
mainso the diff now contains only the 3.0.0 change.user.name/user.idfor these IAM events stop matching new data. Thechangelog entry (surfaced by Kibana's upgrade acknowledgment prompt) tells
users what changed, why, and to migrate content to
user.target.*.enough release time has passed between the expand and contract phases for
users to migrate, and hold this PR if not.
for
security_detection_engine): the Linux User Account Creation rule(
edfd5ca9-9d6c-44d9-b615-1e56b920219c) still matches as intended, but theosquery investigation queries in its
notefield use{{user.name}}andshould switch to
{{user.target.name}}.How to test this PR locally
Or simulate directly:
with useradd/usermod/userdel/passwd-chauthtok sample events (see
#20105) and verify the affected account appears only in
user.target.*(plusrelated.user), withuser.name/user.idno longerduplicated.
Related issues