[osquerybeat] Fix what events are published for diff queries#48438
Merged
marc-gr merged 2 commits intoelastic:mainfrom Feb 10, 2026
Merged
[osquerybeat] Fix what events are published for diff queries#48438marc-gr merged 2 commits intoelastic:mainfrom
marc-gr merged 2 commits intoelastic:mainfrom
Conversation
Contributor
|
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
Contributor
🤖 GitHub commentsJust comment with:
|
Contributor
|
This pull request does not have a backport label.
To fixup this pull request, you need to add the backport labels for the needed
|
brian-mckinney
approved these changes
Feb 9, 2026
Contributor
|
@Mergifyio backport 8.19 9.2 9.3 |
Contributor
✅ Backports have been createdDetails
|
mergify bot
pushed a commit
that referenced
this pull request
Feb 10, 2026
* Fix what events are published for diff queries * fix: add changelog entry for differential results bug in osquerybeat (cherry picked from commit f2121bf)
4 tasks
mergify bot
pushed a commit
that referenced
this pull request
Feb 10, 2026
* Fix what events are published for diff queries * fix: add changelog entry for differential results bug in osquerybeat (cherry picked from commit f2121bf)
4 tasks
mergify bot
pushed a commit
that referenced
this pull request
Feb 10, 2026
* Fix what events are published for diff queries * fix: add changelog entry for differential results bug in osquerybeat (cherry picked from commit f2121bf)
4 tasks
marc-gr
added a commit
that referenced
this pull request
Feb 16, 2026
* Fix what events are published for diff queries * fix: add changelog entry for differential results bug in osquerybeat (cherry picked from commit f2121bf)
marc-gr
added a commit
that referenced
this pull request
Feb 16, 2026
* Fix what events are published for diff queries * fix: add changelog entry for differential results bug in osquerybeat (cherry picked from commit f2121bf)
marc-gr
added a commit
that referenced
this pull request
Feb 16, 2026
* Fix what events are published for diff queries * fix: add changelog entry for differential results bug in osquerybeat (cherry picked from commit f2121bf)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed commit message
Fix osquerybeat differential results handling with two bugs:
Checklist
I have made corresponding changes to the documentationI have made corresponding change to the default configuration filesstresstest.shscript to run them under stress conditions and race detector to verify their stability../changelog/fragmentsusing the changelog tool.Disruptive User Impact
None. This is a bug fix that corrects incorrect behavior. Users will now receive accurate differential results where "removed" events contain the previous values and "added" events contain the new values.
Related issues