753753 "original" : " /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz" ,
754754 "path" : " /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz"
755755 }
756+ },
757+ {
758+ "@timestamp" : " 2021-07-14T18:57:31.000Z" ,
759+ "aws" : {
760+ "s3access" : {
761+ "aclrequired" : " Yes" ,
762+ "authentication_type" : " AuthHeader" ,
763+ "bucket" : " flow-log-test" ,
764+ "bucket_owner" : " 67797214d75628047d9c76b18a78cded1a4b069b71f2a9d5a53649c38da8770b" ,
765+ "cipher_suite" : " ECDHE-RSA-AES128-GCM-SHA256" ,
766+ "host_header" : " flow-log-test.s3.us-gov-west-1.amazonaws.com" ,
767+ "host_id" : " 02SxwfXpO5UysN0GsKGa3uGDQ6E/W7+Hwo/luRH8p1VEexULoe66RCM+nja0dEq2JqLrtgjocvVRRkVt4=" ,
768+ "http_status" : 200 ,
769+ "key" : " AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-_20210713T1855Z_f12aa632.log.gz" ,
770+ "object_size" : 773 ,
771+ "operation" : " REST.PUT.OBJECT" ,
772+ "point_arn" : " arn:aws:s3:us-west-1:123456789012:accesspoint/example-AP" ,
773+ "request_id" : " MVGXZXEVN3IG9S24" ,
774+ "request_uri" : " PUT /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz HTTP/1.1" ,
775+ "requester" : " svc:delivery.logs.amazonaws.com" ,
776+ "signature_version" : " SigV4" ,
777+ "tls_version" : " TLSv1.2" ,
778+ "total_time" : 103 ,
779+ "turn_around_time" : 13
780+ }
781+ },
782+ "client" : {
783+ "user" : {
784+ "id" : " svc:delivery.logs.amazonaws.com"
785+ }
786+ },
787+ "cloud" : {
788+ "provider" : " aws" ,
789+ "region" : " us-gov-west-1"
790+ },
791+ "ecs" : {
792+ "version" : " 8.11.0"
793+ },
794+ "event" : {
795+ "action" : " REST.PUT.OBJECT" ,
796+ "category" : [
797+ " web"
798+ ],
799+ "duration" : 103000000 ,
800+ "id" : " MVGXZXEVN3IG9S24" ,
801+ "kind" : " event" ,
802+ "original" : " 67797214d75628047d9c76b18a78cded1a4b069b71f2a9d5a53649c38da8770b flow-log-test [14/Jul/2021:18:57:31 +0000] - svc:delivery.logs.amazonaws.com MVGXZXEVN3IG9S24 REST.PUT.OBJECT AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-_20210713T1855Z_f12aa632.log.gz \" PUT /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz HTTP/1.1\" 200 - - 773 103 13 \" -\" \" -\" - 02SxwfXpO5UysN0GsKGa3uGDQ6E/W7+Hwo/luRH8p1VEexULoe66RCM+nja0dEq2JqLrtgjocvVRRkVt4= SigV4 ECDHE-RSA-AES128-GCM-SHA256 AuthHeader flow-log-test.s3.us-gov-west-1.amazonaws.com TLSv1.2 arn:aws:s3:us-west-1:123456789012:accesspoint/example-AP Yes" ,
803+ "outcome" : " success" ,
804+ "type" : [
805+ " access"
806+ ]
807+ },
808+ "http" : {
809+ "request" : {
810+ "method" : " PUT"
811+ },
812+ "response" : {
813+ "status_code" : 200
814+ },
815+ "version" : " 1.1"
816+ },
817+ "related" : {
818+ "user" : [
819+ " 67797214d75628047d9c76b18a78cded1a4b069b71f2a9d5a53649c38da8770b"
820+ ]
821+ },
822+ "tags" : [
823+ " preserve_original_event"
824+ ],
825+ "tls" : {
826+ "cipher" : " ECDHE-RSA-AES128-GCM-SHA256" ,
827+ "version" : " 1.2" ,
828+ "version_protocol" : " tls"
829+ },
830+ "url" : {
831+ "extension" : " gz" ,
832+ "original" : " /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz" ,
833+ "path" : " /AWSLogs/000000000000/vpcflowlogs/us-gov-east-1/2021/07/13/000000000000_vpcflowlogs_us-gov-east-1_fl-0e7c13bf00cf15bfe_20210713T1855Z_f12aa632.log.gz"
834+ }
756835 }
757836 ]
758837}
0 commit comments