Skip to content

Commit c853b07

Browse files
committed
adding grok for awss3 access
Signed-off-by: Andreas Gkizas <andreas.gkizas@elastic.co>
1 parent 45d8b8b commit c853b07

File tree

2 files changed

+82
-3
lines changed

2 files changed

+82
-3
lines changed

packages/aws/changelog.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
# newer versions go on top
22
- version: "2.45.2"
33
changes:
4-
- description: Fix grok pattern for AWS S3 access
5-
type: bugfix
6-
link: https://github.com/elastic/integrations/pull/13350
4+
- description: Update grok pattern for AWS S3 access ingest pipeline
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/13486
77
- version: "2.45.1"
88
changes:
99
- description: Fix handling of SQS worker count configuration.

packages/aws/data_stream/s3access/_dev/test/pipeline/test-s3-server-access.log-expected.json

Lines changed: 79 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -753,6 +753,85 @@
753753
"original": "/AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz",
754754
"path": "/AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz"
755755
}
756+
},
757+
{
758+
"@timestamp": "2021-07-14T18:57:31.000Z",
759+
"aws": {
760+
"s3access": {
761+
"aclrequired": "Yes",
762+
"authentication_type": "AuthHeader",
763+
"bucket": "flow-log-test",
764+
"bucket_owner": "67797214d75628047d9c76b18a78cded1a4b069b71f2a9d5a53649c38da8770b",
765+
"cipher_suite": "ECDHE-RSA-AES128-GCM-SHA256",
766+
"host_header": "flow-log-test.s3.us-gov-west-1.amazonaws.com",
767+
"host_id": "02SxwfXpO5UysN0GsKGa3uGDQ6E/W7+Hwo/luRH8p1VEexULoe66RCM+nja0dEq2JqLrtgjocvVRRkVt4=",
768+
"http_status": 200,
769+
"key": "AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-_20210713T1855Z_f12aa632.log.gz",
770+
"object_size": 773,
771+
"operation": "REST.PUT.OBJECT",
772+
"point_arn": "arn:aws:s3:us-west-1:123456789012:accesspoint/example-AP",
773+
"request_id": "MVGXZXEVN3IG9S24",
774+
"request_uri": "PUT /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz HTTP/1.1",
775+
"requester": "svc:delivery.logs.amazonaws.com",
776+
"signature_version": "SigV4",
777+
"tls_version": "TLSv1.2",
778+
"total_time": 103,
779+
"turn_around_time": 13
780+
}
781+
},
782+
"client": {
783+
"user": {
784+
"id": "svc:delivery.logs.amazonaws.com"
785+
}
786+
},
787+
"cloud": {
788+
"provider": "aws",
789+
"region": "us-gov-west-1"
790+
},
791+
"ecs": {
792+
"version": "8.11.0"
793+
},
794+
"event": {
795+
"action": "REST.PUT.OBJECT",
796+
"category": [
797+
"web"
798+
],
799+
"duration": 103000000,
800+
"id": "MVGXZXEVN3IG9S24",
801+
"kind": "event",
802+
"original": "67797214d75628047d9c76b18a78cded1a4b069b71f2a9d5a53649c38da8770b flow-log-test [14/Jul/2021:18:57:31 +0000] - svc:delivery.logs.amazonaws.com MVGXZXEVN3IG9S24 REST.PUT.OBJECT AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-_20210713T1855Z_f12aa632.log.gz \"PUT /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz HTTP/1.1\" 200 - - 773 103 13 \"-\" \"-\" - 02SxwfXpO5UysN0GsKGa3uGDQ6E/W7+Hwo/luRH8p1VEexULoe66RCM+nja0dEq2JqLrtgjocvVRRkVt4= SigV4 ECDHE-RSA-AES128-GCM-SHA256 AuthHeader flow-log-test.s3.us-gov-west-1.amazonaws.com TLSv1.2 arn:aws:s3:us-west-1:123456789012:accesspoint/example-AP Yes",
803+
"outcome": "success",
804+
"type": [
805+
"access"
806+
]
807+
},
808+
"http": {
809+
"request": {
810+
"method": "PUT"
811+
},
812+
"response": {
813+
"status_code": 200
814+
},
815+
"version": "1.1"
816+
},
817+
"related": {
818+
"user": [
819+
"67797214d75628047d9c76b18a78cded1a4b069b71f2a9d5a53649c38da8770b"
820+
]
821+
},
822+
"tags": [
823+
"preserve_original_event"
824+
],
825+
"tls": {
826+
"cipher": "ECDHE-RSA-AES128-GCM-SHA256",
827+
"version": "1.2",
828+
"version_protocol": "tls"
829+
},
830+
"url": {
831+
"extension": "gz",
832+
"original": "/AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz",
833+
"path": "/AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz"
834+
}
756835
}
757836
]
758837
}

0 commit comments

Comments
 (0)