Skip to content

[Auditbeat] Cherry-pick #12591 to 6.8: Host: Fix reboot detection logic #12595

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jun 18, 2019

Conversation

cwurm
Copy link
Contributor

@cwurm cwurm commented Jun 18, 2019

Cherry-pick of PR #12591 to 6.8 branch. Original message:

On Windows, BootTime is not fully accurate and can vary by a few milliseconds (see Remarks for GetTickCount64). This causes a lot of false positive event.action: reboot events.

This PR changes to only report a reboot if the new BootTime is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second.

On Windows, `BootTime` is not fully accurate and can vary by a few milliseconds. This causes a lot of false positive `event.action: reboot` events.

This changes to only report a reboot if the new `BootTime` is at least 1 second after the old. This should fix Windows and not affect the other platforms, assuming it's impossible to reboot a system twice in 1 second.

(cherry picked from commit 9d73bdc)
@cwurm cwurm changed the title Cherry-pick #12591 to 6.8: [Auditbeat] Host: Fix reboot detection logic [Auditbeat] Cherry-pick #12591 to 6.8: Host: Fix reboot detection logic Jun 18, 2019
@elasticmachine
Copy link
Collaborator

Pinging @elastic/secops

@cwurm cwurm requested a review from adriansr June 18, 2019 10:10
@cwurm cwurm merged commit 39f60c6 into elastic:6.8 Jun 18, 2019
@cwurm cwurm deleted the backport_12591_6.8 branch June 18, 2019 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants