Skip to content
Merged
Show file tree
Hide file tree
Changes from 12 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions packages/iptables/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,22 @@ traffic (allow/deny).
The module is by default configured to run with the `udp` input on port `9001`.
However, it can also be configured to read from a file path or journald.

To read Journald logs from within a container, you need to use a
Docker image variant that contains `journalctl` binary. The variant
supporting Journald is `elastic-agent-complete`.

Journal files can have breaking changes making it
impossible to read files generated by a newer versions of
Journald. Ensure the journal files you are reading were generated by
a version equal to or older than the `journalctl` shipped with the Docker
image.

To check the version of `journalctl` shipped with an Elastic-Agent
Docker image, run the following command:
```
docker run --rm -it --entrypoint journalctl docker.elastic.co/elastic-agent/elastic-agent-complete:<VERSION> --version
```

## Logs

### Iptables log
Expand Down
5 changes: 5 additions & 0 deletions packages/iptables/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.21.1"
changes:
- description: Update documentation to mention the requirements for reading Journald logs.
type: enhancement
link: https://github.com/elastic/integrations/pull/13597
- version: "1.21.0"
changes:
- description: Allow @custom pipeline access to event.original without setting preserve_original_event.
Expand Down
16 changes: 16 additions & 0 deletions packages/iptables/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,22 @@ traffic (allow/deny).
The module is by default configured to run with the `udp` input on port `9001`.
However, it can also be configured to read from a file path or journald.

To read Journald logs from within a container, you need to use a
Docker image variant that contains `journalctl` binary. The variant
supporting Journald is `elastic-agent-complete`.

Journal files can have breaking changes making it
impossible to read files generated by a newer versions of
Journald. Ensure the journal files you are reading were generated by
a version equal to or older than the `journalctl` shipped with the Docker
image.

To check the version of `journalctl` shipped with an Elastic-Agent
Docker image, run the following command:
```
docker run --rm -it --entrypoint journalctl docker.elastic.co/elastic-agent/elastic-agent-complete:<VERSION> --version
```

## Logs

### Iptables log
Expand Down
2 changes: 1 addition & 1 deletion packages/iptables/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: iptables
title: Iptables
version: "1.21.0"
version: "1.21.1"
description: Collect logs from Iptables with Elastic Agent.
type: integration
icons:
Expand Down
5 changes: 5 additions & 0 deletions packages/journald/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.2.1"
changes:
- description: Update documentation to mention the requirements for reading Journald logs.
type: enhancement
link: https://github.com/elastic/integrations/pull/13597
- version: "1.2.0"
changes:
- description: Add support for defining Conditions
Expand Down
16 changes: 16 additions & 0 deletions packages/journald/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,22 @@ The journald input reads the log data and the metadata associated with it.

The journald input is available on Linux systems with `systemd` installed.

To read Journald logs from within a container, you need to use a
Docker image variant that contains `journalctl` binary. The variant
supporting Journald is `elastic-agent-complete`.

Journal files can have breaking changes making it
impossible to read files generated by a newer versions of
Journald. Ensure the journal files you are reading were generated by
a version equal to or older than the `journalctl` shipped with the Docker
image.

To check the version of `journalctl` shipped with an Elastic-Agent
Docker image, run the following command:
```
docker run --rm -it --entrypoint journalctl docker.elastic.co/elastic-agent/elastic-agent-complete:<VERSION> --version
```

An example event looks as follows:

```json
Expand Down
2 changes: 1 addition & 1 deletion packages/journald/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 3.3.0
name: journald
title: "Custom Journald logs"
version: 1.2.0
version: 1.2.1
description: Collect logs from journald with Elastic Agent.
type: input
categories:
Expand Down
16 changes: 16 additions & 0 deletions packages/system/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,22 @@ Each data stream collects different kinds of metric data, which may require dedi
to be fetched and which may vary across operating systems.
Details on the permissions needed for each data stream are available in the [Metrics reference](#metrics-reference).

To read Journald logs from within a container, you need to use a
Docker image variant that contains `journalctl` binary. The variant
supporting Journald is `elastic-agent-complete`.

Journal files can have breaking changes making it
impossible to read files generated by a newer versions of
Journald. Ensure the journal files you are reading were generated by
a version equal to or older than the `journalctl` shipped with the Docker
image.

To check the version of `journalctl` shipped with an Elastic-Agent
Docker image, run the following command:
```
docker run --rm -it --entrypoint journalctl docker.elastic.co/elastic-agent/elastic-agent-complete:<VERSION> --version
```

## Setup

For step-by-step instructions on how to set up an integration, see the
Expand Down
5 changes: 5 additions & 0 deletions packages/system/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "2.3.2"
changes:
- description: Update documentation to mention the requirements for reading Journald logs.
type: enhancement
link: https://github.com/elastic/integrations/pull/13597
- version: "2.3.1"
changes:
- description: Change default to use journald input for SLES 15 SP6.
Expand Down
16 changes: 16 additions & 0 deletions packages/system/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,22 @@ Each data stream collects different kinds of metric data, which may require dedi
to be fetched and which may vary across operating systems.
Details on the permissions needed for each data stream are available in the [Metrics reference](#metrics-reference).

To read Journald logs from within a container, you need to use a
Docker image variant that contains `journalctl` binary. The variant
supporting Journald is `elastic-agent-complete`.

Journal files can have breaking changes making it
impossible to read files generated by a newer versions of
Journald. Ensure the journal files you are reading were generated by
a version equal to or older than the `journalctl` shipped with the Docker
image.

To check the version of `journalctl` shipped with an Elastic-Agent
Docker image, run the following command:
```
docker run --rm -it --entrypoint journalctl docker.elastic.co/elastic-agent/elastic-agent-complete:<VERSION> --version
```

## Setup

For step-by-step instructions on how to set up an integration, see the
Expand Down
2 changes: 1 addition & 1 deletion packages/system/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 3.0.2
name: system
title: System
version: "2.3.1"
version: "2.3.2"
description: Collect system logs and metrics from your servers with Elastic Agent.
type: integration
categories:
Expand Down