Skip to content

Filebeat AWS Module - S3 input support for AWS WAF logs #28121

@octavialarentisgsa

Description

@octavialarentisgsa

Describe the enhancement:
An enhancement to current the Filebeat AWS module to allow parsing of AWS WAF logs directly to ECS format is requested.

Describe a specific use case for the enhancement or feature:
Currently the Filebeat AWS module allows certain AWS logs to be pulled directly from AWS S3 buckets (CloudTrail, CloudWatch, ELB, EC2 etc.). This module does not offer support for WAF logs, which requires custom log format parsing to migrate the raw log format into the ECS format.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions