-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Winlogbeat] Ignore non-compliant event version values #15838
Labels
Comments
andrewkroh
added a commit
to andrewkroh/beats
that referenced
this issue
Jan 24, 2020
This causes the XML parser to ignore Version values that are not unsignedByte values (as defined in the schema). Closes elastic#15838
andrewkroh
added a commit
that referenced
this issue
Jan 25, 2020
This causes the XML parser to ignore Version values that are not unsignedByte values (as defined in the schema). Closes #15838
andrewkroh
added a commit
to andrewkroh/beats
that referenced
this issue
Jan 27, 2020
This causes the XML parser to ignore Version values that are not unsignedByte values (as defined in the schema). Closes elastic#15838 (cherry picked from commit 33f7112)
andrewkroh
added a commit
to andrewkroh/beats
that referenced
this issue
Jan 27, 2020
This causes the XML parser to ignore Version values that are not unsignedByte values (as defined in the schema). Closes elastic#15838 (cherry picked from commit 33f7112)
andrewkroh
added a commit
that referenced
this issue
Jan 29, 2020
andrewkroh
added a commit
that referenced
this issue
Feb 12, 2020
gbanasiak
added a commit
that referenced
this issue
Jun 10, 2020
Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1
andrewkroh
pushed a commit
that referenced
this issue
Aug 10, 2020
Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1
dedemorton
pushed a commit
to dedemorton/beats
that referenced
this issue
Oct 16, 2020
Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1
dedemorton
pushed a commit
to dedemorton/beats
that referenced
this issue
Oct 16, 2020
Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1
dedemorton
added a commit
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (#19105) Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
to dedemorton/beats
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (elastic#19105) Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
to dedemorton/beats
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (elastic#19105) Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
to dedemorton/beats
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (elastic#19105) Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
to dedemorton/beats
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (elastic#19105) Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (#19105) Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co> Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (#19105) Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co> Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (#19105) Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co> Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
dedemorton
added a commit
that referenced
this issue
Oct 16, 2020
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (#19105) Fix for #15838 has first arrived in 7.6.1, not 7.5.0. Verification: v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co> Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
leweafan
pushed a commit
to leweafan/beats
that referenced
this issue
Apr 28, 2023
Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1
leweafan
pushed a commit
to leweafan/beats
that referenced
this issue
Apr 28, 2023
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (elastic#19105) Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co> Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
leweafan
pushed a commit
to leweafan/beats
that referenced
this issue
Apr 28, 2023
* Add 7.7.1 changelog * Fix 15838 issue placement in CHANGELOG (elastic#19105) Fix for elastic#15838 has first arrived in 7.6.1, not 7.5.0. Verification: elastic/beats@v7.6.0...v7.6.1 * Add relnotes link Co-authored-by: Grzegorz Banasiak <grzegorz.banasiak@elastic.co>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The XML schema for Windows event logs defines the
Version
as anunsignedByte
(reference). It contains the version number of the event's definition.Events containing
Version
values that are not uint8 will cause the XML parser to return an error. This results in an event from Winlogbeat with anerror.message
an not much usable data.I propose we make the parsing of
Version
more lenient and simply drop values that are non in the uint8 range. We cannot change the type ofwinlog.version
, which islong
in Elasticsearch, without a breaking change.The text was updated successfully, but these errors were encountered: