Skip to content

[aws_vpcflow_otel] Content pack of EDOT Cloud Forwarder for AWS - VPC Flow Logs#15402

Merged
mykola-elastic merged 28 commits intoelastic:mainfrom
mykola-elastic:vpc-flow-logs-otel-cp
Oct 23, 2025
Merged

[aws_vpcflow_otel] Content pack of EDOT Cloud Forwarder for AWS - VPC Flow Logs#15402
mykola-elastic merged 28 commits intoelastic:mainfrom
mykola-elastic:vpc-flow-logs-otel-cp

Conversation

@mykola-elastic
Copy link
Contributor

@mykola-elastic mykola-elastic commented Sep 19, 2025

Content pack for EDOT Cloud Forwarder for AWS - VPC Flow Logs - Dashboard

Proposed commit message

See title.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices
  • Add auto-install via discovery.datasets

Screenshots

image

@mykola-elastic mykola-elastic self-assigned this Sep 19, 2025
@mykola-elastic mykola-elastic added enhancement New feature or request New Integration Issue or pull request for creating a new integration package. Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] labels Sep 19, 2025
@andrewkroh andrewkroh added dashboard Relates to a Kibana dashboard bug, enhancement, or modification. documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. labels Sep 19, 2025
@mykola-elastic mykola-elastic changed the title Content pack of EDOT Cloud Forwarder for AWS - VPC Flow Logs [aws_vpcflow_otel] Content pack of EDOT Cloud Forwarder for AWS - VPC Flow Logs Sep 22, 2025
@mykola-elastic mykola-elastic marked this pull request as ready for review September 22, 2025 11:09
@mykola-elastic mykola-elastic requested a review from a team as a code owner September 22, 2025 11:09
@mykola-elastic
Copy link
Contributor Author

mykola-elastic commented Sep 22, 2025

For Comparison

The dashboard from AWS package (AWS VPC Flow Logs), added the dashboard and changed some fields to match EDOT Cloud Forwarder for AWS field names

Screenshot 2025-09-22 at 14 36 06 Screenshot 2025-09-22 at 14 36 14

The Dashboard from this PR (using ES|QL)

I removed the map, I don't think I can draw anything on it using the data we have (I may be wrong)

Screenshot 2025-09-22 at 14 38 00

@ishleenk17
Copy link
Member

I removed the map, I don't think I can draw anything on it using the data we have (I may be wrong)

You are right. Till we have geo location fields populated. We can't use the map

Copy link

@daniela-elastic daniela-elastic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, just needs minor tweaking as per my comment.

@mykola-elastic
Copy link
Contributor Author

mykola-elastic commented Sep 26, 2025

@daniela-elastic this one OK?
Screenshot 2025-09-26 at 08 44 26

@elastic-sonarqube
Copy link

@ishleenk17
Copy link
Member

I am good with the PR too.
We will merge the PR once the final dataset changes are out.

cc: @MichaelKatsoulis

@ishleenk17
Copy link
Member

@mykola-elastic : In dashboard under overview we need not mention that we are collecting data through EDOT Cloud forwarder as we will be using the same dashboard for AWS VPC logs via other data flows in AWS.

@mykola-elastic
Copy link
Contributor Author

@ishleenk17 removed it from dashboard

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @mykola-elastic

@MichaelKatsoulis
Copy link
Contributor

@mykola-elastic LGTM. You just need to update the dashboard snapshot because it still references the old filter.

@mykola-elastic
Copy link
Contributor Author

mykola-elastic commented Oct 21, 2025

@MichaelKatsoulis thanks!

I can't find any reference to generic.otel in the dashboard. Did you mean some other filter?

EDIT: Oh, I see, in the PR description, updated, thanks!

Copy link
Member

@ishleenk17 ishleenk17 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

@ishleenk17
Copy link
Member

@mykola-elastic : I was checking in the dashboard, there is no mention of the word "OpenTelemetry" in the title, description of the dashboard. Anyone looking at just the dashboard will not get to know it is having OTEL data.

Do we have this present somewhere ?

@mykola-elastic
Copy link
Contributor Author

@ishleenk17 the dashboard title is [AWS VPC OTEL] VPC Flow Logs Overview

@ishleenk17
Copy link
Member

@ishleenk17 the dashboard title is [AWS VPC OTEL] VPC Flow Logs Overview

Ohk. Missed searching for OTEL.
It would be good to have this as part of description too.
Not a blocker though.

Copy link
Contributor

@lalit-satapathy lalit-satapathy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

triaging approved.

@mykola-elastic mykola-elastic merged commit 6e00355 into elastic:main Oct 23, 2025
7 checks passed
@elastic-vault-github-plugin-prod

Package aws_vpcflow_otel - 0.1.0 containing this change is available at https://epr.elastic.co/package/aws_vpcflow_otel/0.1.0/

@andrewkroh andrewkroh added the Integration:aws_vpcflow_otel AWS VPC Flow Logs OpenTelemetry Assets label Oct 23, 2025
agithomas pushed a commit to agithomas/integrations that referenced this pull request Oct 30, 2025
tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dashboard Relates to a Kibana dashboard bug, enhancement, or modification. documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:aws_vpcflow_otel AWS VPC Flow Logs OpenTelemetry Assets New Integration Issue or pull request for creating a new integration package. Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants