Skip to content

[system/security] - Drop empty process.args token from trailing whitespace - #20907

Merged
ShourieG merged 3 commits into
elastic:mainfrom
ShourieG:bugfix/system_7520
Aug 26, 2026
Merged

ShourieG merged 3 commits into
elastic:mainfrom
ShourieG:bugfix/system_7520

Conversation

@ShourieG

Copy link
Copy Markdown
Contributor

Type of change

  • Bug

Proposed commit message

system.security: drop empty process.args token from trailing whitespace

The Event ID 4688 command-line tokenizer split winlog.event_data.CommandLine
on whitespace but never discarded empty tokens. Windows records a no-argument
process launch with a trailing space after the quoted executable path, so the
final space produced a spurious empty-string element in process.args and
inflated process.args_count by one (e.g. "...\notepad.exe" with a trailing
space yielded args_count 2 instead of 1). Consecutive spaces between real
arguments had the same effect.

Skip empty tokens both when splitting on whitespace and when emitting the
final token, so process.args and process.args_count reflect the actual
argument list. Add a pipeline test case for a no-argument launch with a
trailing space.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

ShourieG and others added 2 commits August 26, 2026 11:52
The Event ID 4688 command-line tokenizer split winlog.event_data.CommandLine
on whitespace but never discarded empty tokens. Windows records a no-argument
process launch with a trailing space after the quoted executable path, so the
final space produced a spurious empty-string element in process.args and
inflated process.args_count by one (e.g. "...\notepad.exe" with a trailing
space yielded args_count 2 instead of 1). Consecutive spaces between real
arguments had the same effect.

Skip empty tokens both when splitting on whitespace and when emitting the
final token, so process.args and process.args_count reflect the actual
argument list. Add a pipeline test case for a no-argument launch with a
trailing space.

Co-authored-by: Cursor <cursoragent@cursor.com>
Add the changelog entry and bump the package version for the
system.security process.args and process.args_count fix.

Co-authored-by: Cursor <cursoragent@cursor.com>
@ShourieG ShourieG self-assigned this Aug 26, 2026
@ShourieG ShourieG added Integration:system System bugfix Pull request that fixes a bug issue Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Aug 26, 2026
@ShourieG
ShourieG marked this pull request as ready for review August 26, 2026 06:29
@ShourieG
ShourieG requested review from a team as code owners August 26, 2026 06:29
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@vera-review-bot

Copy link
Copy Markdown

🟢 No issues across the latest commits fce9be2.

A new commit triggers another review — at most once every 15 minutes. I skip the PR while it's approved or has merge conflicts.

🤖 AI-Generated Review | Vera Review Bot - v0.2.7 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@chemamartinez chemamartinez left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

start = i + 1;
}
if (i == ctx.winlog.event_data.CommandLine.length() - 1) {
if (i == ctx.winlog.event_data.CommandLine.length() - 1 && start <= end) {

@efd6 efd6 Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same code exists in windows forwarded security_standard.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

cc @ShourieG

@mergify

mergify Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@ShourieG
ShourieG merged commit c80c3fb into elastic:main Aug 26, 2026
10 checks passed
@ShourieG
ShourieG deleted the bugfix/system_7520 branch August 26, 2026 08:08
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package system - 2.23.1 containing this change is available at https://epr.elastic.co/package/system/2.23.1/

ShourieG added a commit that referenced this pull request Aug 27, 2026
…tespace (#20911)

windows.forwarded: drop empty process.args token from trailing whitespace

The Event ID 4688 command-line tokenizer split winlog.event_data.CommandLine
on whitespace but never discarded empty tokens. Windows records a no-argument
process launch with a trailing space after the quoted executable path, so the
final space produced a spurious empty-string element in process.args and
inflated process.args_count by one (e.g. "...\notepad.exe" with a trailing
space yielded args_count 2 instead of 1). Consecutive spaces between real
arguments had the same effect. This mirrors the same fix already applied to
the system.security pipeline in #20907.

Skip empty tokens both when splitting on whitespace and when emitting the
final token, so process.args and process.args_count reflect the actual
argument list. Add a pipeline test case for a no-argument launch with a
trailing space and bump the package to 3.9.2.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Integration:system System Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants