|
23 | 23 | "client.user.id": "arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9", |
24 | 24 | "cloud.provider": "aws", |
25 | 25 | "event.action": "REST.GET.LOCATION", |
| 26 | + "event.category": "web", |
26 | 27 | "event.dataset": "aws.s3access", |
27 | | - "event.duration": "17", |
| 28 | + "event.duration": 17000000, |
28 | 29 | "event.id": "44EE8651683CB4DA", |
29 | 30 | "event.kind": "event", |
30 | 31 | "event.module": "aws", |
| 32 | + "event.original": "36c1f05b76016b78528454e6e0c60e2b7ff7aa20c0a5e4c748276e5b0a2debd2 test-s3-ks [01/Aug/2019:00:24:41 +0000] 72.21.217.31 arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9 44EE8651683CB4DA REST.GET.LOCATION - \"GET /test-s3-ks/?location&aws-account=627959692251 HTTP/1.1\" 200 - 142 - 17 - \"-\" \"AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation\" - BsCfJedfuSnds2QFoxi+E/O7M6OEWzJnw4dUaes/2hyA363sONRJKzB7EOY+Bt9DTHYUn+HoHxI= SigV4 ECDHE-RSA-AES128-SHA AuthHeader s3.ap-southeast-1.amazonaws.com TLSv1.2", |
31 | 33 | "event.outcome": "success", |
| 34 | + "event.type": [ |
| 35 | + "access" |
| 36 | + ], |
32 | 37 | "fileset.name": "s3access", |
33 | 38 | "geo.city_name": "Ashburn", |
34 | 39 | "geo.continent_name": "North America", |
|
38 | 43 | "geo.location.lon": -77.4728, |
39 | 44 | "geo.region_iso_code": "US-VA", |
40 | 45 | "geo.region_name": "Virginia", |
| 46 | + "http.request.method": "GET", |
| 47 | + "http.response.body.bytes": 142, |
41 | 48 | "http.response.status_code": 200, |
| 49 | + "http.version": "1.1", |
42 | 50 | "input.type": "log", |
43 | 51 | "log.offset": 0, |
44 | 52 | "related.ip": [ |
|
54 | 62 | "tls.cipher": "ECDHE-RSA-AES128-SHA", |
55 | 63 | "tls.version": "1.2", |
56 | 64 | "tls.version_protocol": "tls", |
| 65 | + "url.original": "/test-s3-ks/?location&aws-account=627959692251", |
| 66 | + "url.path": "/test-s3-ks/", |
| 67 | + "url.query": "location&aws-account=627959692251", |
57 | 68 | "user_agent.device.name": "Other", |
58 | 69 | "user_agent.name": "aws-sdk-java", |
59 | 70 | "user_agent.original": "AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation", |
|
86 | 97 | "client.user.id": "arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9", |
87 | 98 | "cloud.provider": "aws", |
88 | 99 | "event.action": "REST.GET.LOCATION", |
| 100 | + "event.category": "web", |
89 | 101 | "event.dataset": "aws.s3access", |
90 | | - "event.duration": "3", |
| 102 | + "event.duration": 3000000, |
91 | 103 | "event.id": "E26222010BCC32B6", |
92 | 104 | "event.kind": "event", |
93 | 105 | "event.module": "aws", |
| 106 | + "event.original": "36c1f05b76016b78528454e6e0c60e2b7ff7aa20c0a5e4c748276e5b0a2debd2 test-s3-ks [01/Aug/2019:00:24:42 +0000] 72.21.217.31 arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9 E26222010BCC32B6 REST.GET.LOCATION - \"GET /test-s3-ks/?location&aws-account=627959692251 HTTP/1.1\" 200 - 142 - 3 - \"-\" \"AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation\" - gNl/Q1IzY6nGTBygqI3rnMz/ZFOFwOTDpSMrNca+IcEmMAd6sCIs1ZRLYDekD8LB9lrj9UdQLWE= SigV4 ECDHE-RSA-AES128-SHA AuthHeader s3.ap-southeast-1.amazonaws.com TLSv1.2", |
94 | 107 | "event.outcome": "success", |
| 108 | + "event.type": [ |
| 109 | + "access" |
| 110 | + ], |
95 | 111 | "fileset.name": "s3access", |
96 | 112 | "geo.city_name": "Ashburn", |
97 | 113 | "geo.continent_name": "North America", |
|
101 | 117 | "geo.location.lon": -77.4728, |
102 | 118 | "geo.region_iso_code": "US-VA", |
103 | 119 | "geo.region_name": "Virginia", |
| 120 | + "http.request.method": "GET", |
| 121 | + "http.response.body.bytes": 142, |
104 | 122 | "http.response.status_code": 200, |
| 123 | + "http.version": "1.1", |
105 | 124 | "input.type": "log", |
106 | 125 | "log.offset": 715, |
107 | 126 | "related.ip": [ |
|
117 | 136 | "tls.cipher": "ECDHE-RSA-AES128-SHA", |
118 | 137 | "tls.version": "1.2", |
119 | 138 | "tls.version_protocol": "tls", |
| 139 | + "url.original": "/test-s3-ks/?location&aws-account=627959692251", |
| 140 | + "url.path": "/test-s3-ks/", |
| 141 | + "url.query": "location&aws-account=627959692251", |
120 | 142 | "user_agent.device.name": "Other", |
121 | 143 | "user_agent.name": "aws-sdk-java", |
122 | 144 | "user_agent.original": "AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation", |
|
150 | 172 | "client.user.id": "arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9", |
151 | 173 | "cloud.provider": "aws", |
152 | 174 | "event.action": "REST.GET.BUCKET", |
| 175 | + "event.category": "web", |
153 | 176 | "event.dataset": "aws.s3access", |
154 | | - "event.duration": "2", |
| 177 | + "event.duration": 2000000, |
155 | 178 | "event.id": "4DD6D17D1C5C401C", |
156 | 179 | "event.kind": "event", |
157 | 180 | "event.module": "aws", |
| 181 | + "event.original": "36c1f05b76016b78528454e6e0c60e2b7ff7aa20c0a5e4c748276e5b0a2debd2 test-s3-ks [01/Aug/2019:00:24:43 +0000] 72.21.217.31 arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9 4DD6D17D1C5C401C REST.GET.BUCKET - \"GET /test-s3-ks/?max-keys=0&encoding-type=url&aws-account=627959692251 HTTP/1.1\" 200 - 265 - 2 1 \"-\" \"AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation\" - KzvchfojYQnuFC4PABYVJVxIlv/f6r17LRaTSvw7x+bxj4PkkPKT1kX9x8wbqtq40iD4PC881iE= SigV4 ECDHE-RSA-AES128-SHA AuthHeader s3.ap-southeast-1.amazonaws.com TLSv1.2", |
158 | 182 | "event.outcome": "success", |
| 183 | + "event.type": [ |
| 184 | + "access" |
| 185 | + ], |
159 | 186 | "fileset.name": "s3access", |
160 | 187 | "geo.city_name": "Ashburn", |
161 | 188 | "geo.continent_name": "North America", |
|
165 | 192 | "geo.location.lon": -77.4728, |
166 | 193 | "geo.region_iso_code": "US-VA", |
167 | 194 | "geo.region_name": "Virginia", |
| 195 | + "http.request.method": "GET", |
| 196 | + "http.response.body.bytes": 265, |
168 | 197 | "http.response.status_code": 200, |
| 198 | + "http.version": "1.1", |
169 | 199 | "input.type": "log", |
170 | 200 | "log.offset": 1429, |
171 | 201 | "related.ip": [ |
|
181 | 211 | "tls.cipher": "ECDHE-RSA-AES128-SHA", |
182 | 212 | "tls.version": "1.2", |
183 | 213 | "tls.version_protocol": "tls", |
| 214 | + "url.original": "/test-s3-ks/?max-keys=0&encoding-type=url&aws-account=627959692251", |
| 215 | + "url.path": "/test-s3-ks/", |
| 216 | + "url.query": "max-keys=0&encoding-type=url&aws-account=627959692251", |
184 | 217 | "user_agent.device.name": "Other", |
185 | 218 | "user_agent.name": "aws-sdk-java", |
186 | 219 | "user_agent.original": "AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation", |
|
213 | 246 | "client.user.id": "arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9", |
214 | 247 | "cloud.provider": "aws", |
215 | 248 | "event.action": "REST.GET.LOCATION", |
| 249 | + "event.category": "web", |
216 | 250 | "event.dataset": "aws.s3access", |
217 | | - "event.duration": "4", |
| 251 | + "event.duration": 4000000, |
218 | 252 | "event.id": "706992E2F3CC3C3D", |
219 | 253 | "event.kind": "event", |
220 | 254 | "event.module": "aws", |
| 255 | + "event.original": "36c1f05b76016b78528454e6e0c60e2b7ff7aa20c0a5e4c748276e5b0a2debd2 test-s3-ks [01/Aug/2019:00:24:43 +0000] 72.21.217.31 arn:aws:sts::123456:assumed-role/AWSServiceRoleForTrustedAdvisor/TrustedAdvisor_627959692251_784ab70b-8cc9-4d37-a2ec-2ff4d0c08af9 706992E2F3CC3C3D REST.GET.LOCATION - \"GET /test-s3-ks/?location&aws-account=627959692251 HTTP/1.1\" 200 - 142 - 4 - \"-\" \"AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation\" - cIN12KTrJwx+uTBZD+opZUPE4iGypi8oG/oXGPzFk9CMuHQGuEpmAeNELdtYKDxf2TDor25Nikg= SigV4 ECDHE-RSA-AES128-SHA AuthHeader s3.ap-southeast-1.amazonaws.com TLSv1.2", |
221 | 256 | "event.outcome": "success", |
| 257 | + "event.type": [ |
| 258 | + "access" |
| 259 | + ], |
222 | 260 | "fileset.name": "s3access", |
223 | 261 | "geo.city_name": "Ashburn", |
224 | 262 | "geo.continent_name": "North America", |
|
228 | 266 | "geo.location.lon": -77.4728, |
229 | 267 | "geo.region_iso_code": "US-VA", |
230 | 268 | "geo.region_name": "Virginia", |
| 269 | + "http.request.method": "GET", |
| 270 | + "http.response.body.bytes": 142, |
231 | 271 | "http.response.status_code": 200, |
| 272 | + "http.version": "1.1", |
232 | 273 | "input.type": "log", |
233 | 274 | "log.offset": 2161, |
234 | 275 | "related.ip": [ |
|
244 | 285 | "tls.cipher": "ECDHE-RSA-AES128-SHA", |
245 | 286 | "tls.version": "1.2", |
246 | 287 | "tls.version_protocol": "tls", |
| 288 | + "url.original": "/test-s3-ks/?location&aws-account=627959692251", |
| 289 | + "url.path": "/test-s3-ks/", |
| 290 | + "url.query": "location&aws-account=627959692251", |
247 | 291 | "user_agent.device.name": "Other", |
248 | 292 | "user_agent.name": "aws-sdk-java", |
249 | 293 | "user_agent.original": "AWS-Support-TrustedAdvisor, aws-internal/3 aws-sdk-java/1.11.590 Linux/4.9.137-0.1.ac.218.74.329.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.212-b03 java/1.8.0_212 vendor/Oracle_Corporation", |
|
274 | 318 | "client.user.id": "arn:aws:iam::123456:user/test@elastic.co", |
275 | 319 | "cloud.provider": "aws", |
276 | 320 | "event.action": "BATCH.DELETE.OBJECT", |
| 321 | + "event.category": "web", |
277 | 322 | "event.dataset": "aws.s3access", |
278 | 323 | "event.id": "8CD7A4A71E2E5C9E", |
279 | 324 | "event.kind": "event", |
280 | 325 | "event.module": "aws", |
| 326 | + "event.original": "36c1f05b76016b78528454e6e0c60e2b7ff7aa20c0a5e4c748276e5b0a2debd2 jsoriano-s3-test [10/Sep/2019:15:11:07 +0000] 77.227.156.41 arn:aws:iam::123456:user/test@elastic.co 8CD7A4A71E2E5C9E BATCH.DELETE.OBJECT jolokia-war-1.5.0.war - 204 - - 344017 - - - - - IeDW5I3wefFxU8iHOcAzi5qr+O+1bdRlcQ0AO2WGjFh7JwYM6qCoKq+1TrUshrXMlBxPFtg97Vk= SigV4 ECDHE-RSA-AES128-SHA AuthHeader s3.eu-central-1.amazonaws.com TLSv1.2", |
281 | 327 | "event.outcome": "success", |
| 328 | + "event.type": [ |
| 329 | + "access" |
| 330 | + ], |
282 | 331 | "fileset.name": "s3access", |
283 | 332 | "geo.city_name": "Teruel", |
284 | 333 | "geo.continent_name": "Europe", |
|
327 | 376 | "client.user.id": "arn:aws:iam::123456:user/test@elastic.co", |
328 | 377 | "cloud.provider": "aws", |
329 | 378 | "event.action": "BATCH.DELETE.OBJECT", |
| 379 | + "event.category": "web", |
330 | 380 | "event.dataset": "aws.s3access", |
331 | 381 | "event.id": "6CE38F1312D32BDD", |
332 | 382 | "event.kind": "event", |
333 | 383 | "event.module": "aws", |
| 384 | + "event.original": "36c1f05b76016b78528454e6e0c60e2b7ff7aa20c0a5e4c748276e5b0a2debd2 test-s3-ks [19/Sep/2019:17:06:39 +0000] 174.29.206.152 arn:aws:iam::123456:user/test@elastic.co 6CE38F1312D32BDD BATCH.DELETE.OBJECT Screen+Shot+2019-09-09+at+9.08.44+AM.png - 204 - - 57138 - - - - - LwRa4w6DbuU48GKQiH3jDbjfTyLCbwasFBsdttugRQ+9lH4jK8lT91+HhGZKMYI3sPyKuQ9LvU0= SigV4 ECDHE-RSA-AES128-SHA AuthHeader s3-ap-southeast-1.amazonaws.com TLSv1.2", |
334 | 385 | "event.outcome": "success", |
| 386 | + "event.type": [ |
| 387 | + "access" |
| 388 | + ], |
335 | 389 | "fileset.name": "s3access", |
336 | 390 | "geo.city_name": "Denver", |
337 | 391 | "geo.continent_name": "North America", |
|
0 commit comments