Cherry-pick #10137 to 6.6: Teach elasticsearch/audit fileset to parse out some more fields #10413
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Cherry-pick of PR #10137 to 6.6 branch. Original message:
Resolves #10134.
This PR teaches the
elasticsearch/audit
fileset to parse out a few more fields, viz:elasticsearch.audit.realm
,elasticsearch.audit.roles
elasticsearch.audit.indices
It also teaches the fileset to parse
elasticsearch.audit.action
values that themselves contain[
and]
delimiters around sub-actions, e.g.action=[indices:data/read/search[free_context]]
.