-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Auditbeat] Host: Fix reboot detection logic #12591
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Pinging @elastic/secops |
adriansr
approved these changes
Jun 18, 2019
cwurm
pushed a commit
to cwurm/beats
that referenced
this pull request
Jun 18, 2019
On Windows, `BootTime` is not fully accurate and can vary by a few milliseconds. This causes a lot of false positive `event.action: reboot` events. This changes to only report a reboot if the new `BootTime` is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second. (cherry picked from commit 9d73bdc)
cwurm
pushed a commit
to cwurm/beats
that referenced
this pull request
Jun 18, 2019
On Windows, `BootTime` is not fully accurate and can vary by a few milliseconds. This causes a lot of false positive `event.action: reboot` events. This changes to only report a reboot if the new `BootTime` is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second. (cherry picked from commit 9d73bdc)
cwurm
pushed a commit
that referenced
this pull request
Jun 18, 2019
…ic (#12594) On Windows, `BootTime` is not fully accurate and can vary by a few milliseconds. This causes a lot of false positive `event.action: reboot` events. This changes to only report a reboot if the new `BootTime` is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second. (cherry picked from commit 9d73bdc)
cwurm
pushed a commit
that referenced
this pull request
Jun 18, 2019
…ic (#12595) On Windows, `BootTime` is not fully accurate and can vary by a few milliseconds. This causes a lot of false positive `event.action: reboot` events. This changes to only report a reboot if the new `BootTime` is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second. (cherry picked from commit 9d73bdc)
leweafan
pushed a commit
to leweafan/beats
that referenced
this pull request
Apr 28, 2023
…ion logic (elastic#12594) On Windows, `BootTime` is not fully accurate and can vary by a few milliseconds. This causes a lot of false positive `event.action: reboot` events. This changes to only report a reboot if the new `BootTime` is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second. (cherry picked from commit 4c44828)
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
On Windows,
BootTime
is not fully accurate and can vary by a few milliseconds (seeRemarks
for GetTickCount64). This causes a lot of false positiveevent.action: reboot
events.This PR changes to only report a reboot if the new
BootTime
is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second.