Skip to content

auditd: assign stable name to logfile input - #21093

Draft
efd6 wants to merge 1 commit into
elastic:mainfrom
efd6:20643-auditd-2a
Draft

auditd: assign stable name to logfile input#21093
efd6 wants to merge 1 commit into
elastic:mainfrom
efd6:20643-auditd-2a

Conversation

@efd6

@efd6 efd6 commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Proposed commit message

auditd: assign stable name to logfile input

Give the policy-template logfile input a stable name (auditd-logfile)
so that Fleet identifies it by name across upgrades. Fleet's var
carry-over mechanism uses the input name when present, so naming the
input now ensures users keep their customised paths, tags, and
processors when the input type changes in a future release.

Bump format_version from 3.0.0 to 3.6.0, which the package-spec
requires to permit the name field on policy-template inputs. No
behaviour change otherwise.

Upgrade note: the next release changes the input type from logfile to
filestream. To preserve custom variable values, upgrade to this version
first and confirm the policy is applied before upgrading further.
Do not skip this version.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

@efd6 efd6 self-assigned this Sep 7, 2026
@efd6 efd6 added enhancement New feature or request Integration:auditd Auditd Logs Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Sep 7, 2026
@efd6 efd6 changed the title auditd: assign stable name to logfile input (v3.25.0) auditd: assign stable name to logfile input Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@efd6
efd6 force-pushed the 20643-auditd-2a branch 4 times, most recently from 7eb6a91 to 9d81389 Compare September 7, 2026 09:57
Give the policy-template logfile input a stable name (auditd-logfile)
so that Fleet identifies it by name across upgrades. Fleet's var
carry-over mechanism uses the input name when present, so naming the
input now ensures users keep their customised paths, tags, and
processors when the input type changes in a future release.

Bump format_version from 3.0.0 to 3.6.0, which the package-spec
requires to permit the name field on policy-template inputs. No
behaviour change otherwise.

Upgrade note: the next release changes the input type from logfile to
filestream. To preserve custom variable values, upgrade to this version
first and confirm the policy is applied before upgrading further.
Do not skip this version.
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @efd6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:auditd Auditd Logs Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant