Skip to content

[AWS CloudTrail] Map aws.cloudtrail.recipient_account_id to cloud.account.id field#15217

Merged
moxarth-rathod merged 8 commits intoelastic:mainfrom
moxarth-rathod:aws-cloud-trail-15057
Sep 11, 2025
Merged

[AWS CloudTrail] Map aws.cloudtrail.recipient_account_id to cloud.account.id field#15217
moxarth-rathod merged 8 commits intoelastic:mainfrom
moxarth-rathod:aws-cloud-trail-15057

Conversation

@moxarth-rathod
Copy link
Copy Markdown
Contributor

@moxarth-rathod moxarth-rathod commented Sep 8, 2025

Proposed commit message

aws: map aws.cloudtrail.recipient_account_id to cloud.account.id for cloudtrail data stream

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install the elastic package locally.
  • Start the elastic stack using the elastic package.
  • Move to integrations/packages/aws directory.
  • Run the following command to run tests.

elastic-package test -v

Related issues

@moxarth-rathod moxarth-rathod self-assigned this Sep 8, 2025
@moxarth-rathod moxarth-rathod requested review from a team as code owners September 8, 2025 07:52
@moxarth-rathod moxarth-rathod added enhancement New feature or request Integration:aws AWS Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Sep 8, 2025
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Copy link
Copy Markdown
Contributor

@ShourieG ShourieG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@andrewkroh andrewkroh added documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] labels Sep 8, 2025
@moxarth-rathod moxarth-rathod enabled auto-merge (squash) September 8, 2025 12:21
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

elastic-vault-github-plugin-prod bot commented Sep 8, 2025

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@moxarth-rathod moxarth-rathod enabled auto-merge (squash) September 10, 2025 05:41
@moxarth-rathod
Copy link
Copy Markdown
Contributor Author

/test

- description: Map `recipient_account_id` to `cloud.account.id` for AWS CloudTrail.
type: enhancement
link: https://github.com/elastic/integrations/pull/15217
- version: "3.14.2"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we upgrade the previous version here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, my bad - I was working on two AWS PRs at the same time, and that caused the mix-up. Thanks for catching it.

@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

History

cc @moxarth-rathod

@elastic-sonarqube
Copy link
Copy Markdown

@moxarth-rathod moxarth-rathod merged commit 4c355ef into elastic:main Sep 11, 2025
9 checks passed
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

Package aws - 3.16.0 containing this change is available at https://epr.elastic.co/package/aws/3.16.0/

tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
…account.id` field (elastic#15217)

aws:  map a field `aws.cloudtrail.recipient_account_id` to `cloud.account.id` for cloudtrail data stream.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:aws AWS Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants