Skip to content

[AI-5124] DDS: Linux Audit Logs Integration v1.0.0 #19907

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 29 commits into from
May 13, 2025

Conversation

akaila-crest
Copy link
Contributor

@akaila-crest akaila-crest commented Mar 21, 2025

What does this PR do?

This is an initial release PR of Linux Audit Logs integration including all the required assets. This is agent based integration.

Additional Notes

  • OOTB detection rules JSON would be shared separately with the required teams as a part of separate repository .
  • Since during the standard attribute remapping we are not preserving the source attributes as per suggested best practices, it would result in filters using these standard attributes populating the values of other integrations as well as per current datadog behaviour.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@akaila-crest akaila-crest changed the title DDS: Linux Audit Logs Integration v1.0.0 [AI-5124] DDS: Linux Audit Logs Integration v1.0.0 Mar 25, 2025
@akaila-crest akaila-crest marked this pull request as ready for review March 25, 2025 10:48
@akaila-crest akaila-crest requested review from a team as code owners March 25, 2025 10:48
@akaila-crest akaila-crest requested a review from brunorenier May 3, 2025 06:04
@brunorenier brunorenier added the assets/deploy-logs-staging ONLY USED BY Logs Backend - Validates that a PR is OK to go to staging label May 6, 2025
@temporal-github-worker-1 temporal-github-worker-1 bot dismissed nubtron’s stale review May 7, 2025 06:24

Review from nubtron is dismissed. Related teams and files:

  • agent-integrations
    • .github/CODEOWNERS
    • .github/workflows/config/labeler.yml
Copy link
Contributor

@brunorenier brunorenier left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM for Logs, thanks for making the changes and sorry for all the delays.

nubtron
nubtron previously approved these changes May 12, 2025
@temporal-github-worker-1 temporal-github-worker-1 bot dismissed nubtron’s stale review May 12, 2025 14:56

Review from nubtron is dismissed. Related teams and files:

  • agent-integrations
    • .github/CODEOWNERS
@nubtron nubtron requested a review from estherk15 May 12, 2025 15:45
nubtron
nubtron previously approved these changes May 12, 2025
@temporal-github-worker-1 temporal-github-worker-1 bot dismissed nubtron’s stale review May 13, 2025 06:22

Review from nubtron is dismissed. Related teams and files:

  • agent-integrations
    • .github/workflows/config/labeler.yml
@nubtron nubtron merged commit f974b61 into DataDog:master May 13, 2025
35 of 36 checks passed
github-actions bot pushed a commit that referenced this pull request May 13, 2025
Copy link

@jnhunsberger jnhunsberger left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants