Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security usage data #110532

Closed
jportner opened this issue Aug 30, 2021 · 1 comment · Fixed by #110548
Closed

Security usage data #110532

jportner opened this issue Aug 30, 2021 · 1 comment · Fixed by #110548
Assignees
Labels
enhancement New value added to drive a business result Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!

Comments

@jportner
Copy link
Contributor

jportner commented Aug 30, 2021

This is an issue for multiple pieces of security usage data that we need to augment.

Audit logging

In #82578, we originally planned to remove the legacy audit logger in 8.0. However, preliminary analysis of usage data revealed a not-insignificant number of clusters that support audit logging and have it enabled. That, plus the low impact it takes for us to leave legacy audit logging in place, convinced us to push this breaking change out to a future release.

When we do eventually want to remove legacy audit logging, we'll need to understand how many people are still relying on it. Our usage data currently only tells us whether audit logging is enabled or not. We need to update it to also tell us what kind of audit logging is configured.

Elasticsearch configuration

In #48247, we deprecated using elasticsearch.username: elastic in your kibana.yml file, and in #63186 we deprecated the kibana user entirely. Users should set elasticsearch.username: kibana_system instead.
However, it is a low impact for us to continue supporting this for the time being, so we have decided to leave it in place. We do want to collect additional usage data to determine if users are relying on the elastic or kibana users.

@jportner jportner added the enhancement New value added to drive a business result label Aug 30, 2021
@jportner jportner self-assigned this Aug 30, 2021
@botelastic botelastic bot added the needs-team Issues missing a team label label Aug 30, 2021
@jportner jportner added the Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! label Aug 30, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-security (Team:Security)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Aug 30, 2021
@jportner jportner changed the title Audit logging usage data Security usage data Aug 30, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants