Skip to content

[AWS] Fix cloudtrail pipeline to accept us-gov arn#16905

Merged
kaiyan-sheng merged 2 commits intomainfrom
aws_cloudtrail_gov
Jan 9, 2026
Merged

[AWS] Fix cloudtrail pipeline to accept us-gov arn#16905
kaiyan-sheng merged 2 commits intomainfrom
aws_cloudtrail_gov

Conversation

@kaiyan-sheng
Copy link
Copy Markdown

@kaiyan-sheng kaiyan-sheng commented Jan 8, 2026

Proposed commit message

This PR fixed two small things in AWS Cloudtrail ingest pipeline:

  1. It added support for extracting user name from AWS GovCloud STS ARNs
  2. It also fixed management_event field type conversion.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

Sample log is added already.

@kaiyan-sheng kaiyan-sheng requested a review from a team as a code owner January 8, 2026 18:17
@kaiyan-sheng kaiyan-sheng requested review from a team as code owners January 8, 2026 18:29
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

@andrewkroh andrewkroh added Integration:aws AWS Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Jan 8, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@kaiyan-sheng kaiyan-sheng merged commit d4b5bea into main Jan 9, 2026
8 checks passed
@kaiyan-sheng kaiyan-sheng deleted the aws_cloudtrail_gov branch January 9, 2026 15:36
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

Package aws - 5.5.1 containing this change is available at https://epr.elastic.co/package/aws/5.5.1/

jakubgalecki0 pushed a commit to jakubgalecki0/integrations that referenced this pull request Feb 19, 2026
* Fix aws cloudtrail pipeline to accept us-gov arn

* add changelog
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:aws AWS Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants