feat(cloudtrail): add AWS SSM related request data to extracted fields#1196
feat(cloudtrail): add AWS SSM related request data to extracted fields#1196Zaulao wants to merge 1 commit intofalcosecurity:mainfrom
Conversation
|
I guess it was a bad idea to open that PR during a GitHub incident, huh? |
Ahah right! I restarted the CI, let's see 💪 |
Rules files suggestionsrulesComparing No changes detected |
|
Hey @Zaulao . Could you please rebase and add the DCO to your commit? |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Zaulao The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
993ad6c to
5186e26
Compare
Rules files suggestionsrulesComparing No changes detected rulesComparing No changes detected rulesComparing No changes detected rulesComparing No changes detected |
|
I think I messed up something on the rebase but it's working, the CI fail seems intermittent |
Rules files suggestionsrulesComparing No changes detected rulesComparing No changes detected rulesComparing No changes detected rulesComparing No changes detected |
|
Mmm you included commits from dependabot. I guess those should be already on master... Could you please remove them? |
34e68d4 to
e7aa923
Compare
Rules files suggestionsrulesComparing No changes detected |
Rules files suggestionsrulesComparing No changes detected |
leogr
left a comment
There was a problem hiding this comment.
Hey @Zaulao
our policy doesn't allow merge commits
Can you rebase and remove them?
This resource may help https://github.com/falcosecurity/.github/blob/main/CONTRIBUTING.md#resolving-conflicts-by-rebasing
🙏
Signed-off-by: Zaulao <29334377+Zaulao@users.noreply.github.com>
54ff457 to
5c8c025
Compare
|
Sorry for the back and forth, everything should be in order now. |
What type of PR is this?
/kind feature
Any specific area of the project related to this PR?
/area plugins
What this PR does / why we need it:
This PR adds three new fields to the
cloudtrailplugin, which extract the values from therequestParameters.reason,requestParameters.target, andrequestParameters.documentNamefields. These fields are used in ssm:StartSession requests and are useful for monitoring the opening of EC2 connections via Session Manager.Which issue(s) this PR fixes:
Fixes #
Special notes for your reviewer: