Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for collecting user name on FIM (File Integrity Monitoring) #36934

Open
jasoncyp opened this issue Oct 23, 2023 · 6 comments
Open
Assignees
Labels
Auditbeat Team:Elastic-Agent Label for the Agent team Team:Security-Windows Platform Windows Platform Team in Security Solution

Comments

@jasoncyp
Copy link

Describe the enhancement:
FIM module collect the user name info and visualize in user.name field on both Linux and Windows

Describe a specific use case for the enhancement or feature:

User/customer has FIM requirements due to they are FSI industry. For the compliance requirements, customer needs to monitor the critical path to understand what has been changed, who does the change, who is the file owner and in which platform etc..

Most of features our FIM integration can support except the user name

This make the FIM module is not quite out-of-the-box to replace other existing solution. This will be our added value to talk about Elastic platform when comes to security compliance.

@jasoncyp jasoncyp added Auditbeat Team:Elastic-Agent Label for the Agent team labels Oct 23, 2023
@jasoncyp jasoncyp self-assigned this Oct 23, 2023
@jamiehynds
Copy link

jamiehynds commented Oct 26, 2023

@jasoncyp This is something we're currently working on for Linux. We're looking for more information from any users interested in this capability, to ensure we're providing enough coverage across Linux kernels. Would you mind sending this form to any users interested: Elastic Security - Linux Questionnaire

cc @norrietaylor

@ck-elastic
Copy link

Hi @jamiehynds I'm CK, the CA for OCBC. There's a huge expansion (S$2m) opportunity for my customer, OCBC, and they badly want this feature to be able to ensure file integrity as they are running a huge enterprise stack and keeping track of who change what is critical to the success of the expansion.

@norrietaylor
Copy link
Member

@ck-elastic
We shipped this capability for Linux in 8.14. For Windows, it is still outstanding.

Is OCBC interested in both Windows and Linux?

@ck-elastic
Copy link

@norrietaylor Thank you for your info. Customer is interested in Linux for now but FIM for Windows will definitely come very soon after they complete the testing on Linux.

@norrietaylor norrietaylor added the Team:Security-Linux Platform Linux Platform Team in Security Solution label Nov 5, 2024
@elasticmachine
Copy link
Collaborator

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)

@norrietaylor norrietaylor added Team:Security-Windows Platform Windows Platform Team in Security Solution and removed Team:Security-Linux Platform Linux Platform Team in Security Solution labels Nov 5, 2024
@elasticmachine
Copy link
Collaborator

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Auditbeat Team:Elastic-Agent Label for the Agent team Team:Security-Windows Platform Windows Platform Team in Security Solution
Projects
None yet
Development

No branches or pull requests

5 participants