Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
8676f50
Add input groups to AWS package
kaiyan-sheng Mar 8, 2021
bc75787
add input group for logs
kaiyan-sheng Mar 8, 2021
80df5ac
add changelog
kaiyan-sheng Mar 8, 2021
a249acf
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Mar 23, 2021
177a95e
run elastic-package build to generate new policy template level readmes
kaiyan-sheng Mar 23, 2021
ff29085
Merge branch 'master' into aws_with_input_groups
kaiyan-sheng Mar 23, 2021
e00cbd7
rerun elastic-package build
kaiyan-sheng Mar 23, 2021
40cf7c6
move vars into data streams
kaiyan-sheng Apr 6, 2021
92f0271
add input_groups into manifest.yml
kaiyan-sheng Apr 7, 2021
636fe48
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Apr 7, 2021
e4671bd
add httpjson input for cloudtrail
kaiyan-sheng Apr 7, 2021
b3468b7
add missing input group
kaiyan-sheng Apr 8, 2021
49e7d96
remove defined input groups logs and metrics
kaiyan-sheng Apr 12, 2021
53d0448
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Apr 12, 2021
940cb86
Update package version
jen-huang May 11, 2021
bc32c6e
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng May 19, 2021
e0456dd
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Jun 8, 2021
2302926
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Jun 17, 2021
aa0138b
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Jun 22, 2021
9378b04
update version
kaiyan-sheng Jun 22, 2021
590365e
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Jun 28, 2021
1d6b125
Merge remote-tracking branch 'upstream/master' into aws_with_input_gr…
kaiyan-sheng Jun 29, 2021
1795121
run elastic-package format
kaiyan-sheng Jun 29, 2021
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
rerun elastic-package build
  • Loading branch information
kaiyan-sheng committed Mar 23, 2021
commit e00cbd7ecfcfd9c6229697fc3dbd4f75222cdd0e
1 change: 1 addition & 0 deletions packages/aws/docs/billing.md
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,7 @@ An example event for `billing` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/cloudtrail.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,7 @@ events for the account. If user creates a trail, it delivers those events as log
| data_stream.dataset | Data stream dataset. | constant_keyword |
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| event.action | The action captured by the event. | keyword |
| event.ingested | Timestamp when an event arrived in the central data store. | date |
Expand Down
3 changes: 3 additions & 0 deletions packages/aws/docs/cloudwatch.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,8 @@ setup already.
| data_stream.dataset | Data stream dataset. | constant_keyword |
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down Expand Up @@ -135,6 +137,7 @@ An example event for `cloudwatch` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/dynamodb.md
Original file line number Diff line number Diff line change
Expand Up @@ -121,6 +121,7 @@ An example event for `dynamodb` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/ebs.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,7 @@ An example event for `ebs` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
3 changes: 3 additions & 0 deletions packages/aws/docs/ec2.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,8 @@ and `process.name`. For logs from other services, please use `cloudwatch` datase
| data_stream.dataset | Data stream dataset. | constant_keyword |
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down Expand Up @@ -230,6 +232,7 @@ An example event for `ec2` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.cpu.pct | Percent CPU used. This value is normalized by the number of CPU cores and it ranges from 0 to 1. | scaled_float |
Expand Down
3 changes: 3 additions & 0 deletions packages/aws/docs/elb.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,8 @@ For network load balancer, please follow [enable access log for network load bal
| data_stream.type | Data stream type. | constant_keyword |
| destination.bytes | Bytes sent from the destination to the source. | long |
| destination.domain | Destination domain. | keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| event.category | Event category (e.g. database) | keyword |
| event.end | event.end contains the date when the event ended or when the activity was last observed. | date |
| event.kind | Event kind (e.g. event, alert, metric, state, pipeline_error, sig | keyword |
Expand Down Expand Up @@ -261,6 +263,7 @@ An example event for `elb` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/lambda.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,7 @@ An example event for `lambda` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/natgateway.md
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,7 @@ An example event for `natgateway` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/rds.md
Original file line number Diff line number Diff line change
Expand Up @@ -204,6 +204,7 @@ An example event for `rds` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
4 changes: 4 additions & 0 deletions packages/aws/docs/s3.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,8 @@ for sending server access logs to S3 bucket.
| data_stream.dataset | Data stream dataset. | constant_keyword |
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| event.action | The action captured by the event. | keyword |
| event.code | Identification code for this event, if one exists. | keyword |
| event.duration | Duration of the event in nanoseconds. | long |
Expand Down Expand Up @@ -197,6 +199,7 @@ An example event for `s3_daily_storage` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down Expand Up @@ -330,6 +333,7 @@ An example event for `s3_request` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/sns.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,7 @@ An example event for `sns` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/sqs.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,7 @@ An example event for `sqs` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/transitgateway.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,7 @@ An example event for `transitgateway` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/usage.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,7 @@ An example event for `usage` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
6 changes: 5 additions & 1 deletion packages/aws/docs/vpcflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@
| cloud.instance.name | Instance name of the host machine. | keyword |
| cloud.machine.type | Machine type of the host machine. | keyword |
| cloud.project.id | Name of the project in Google Cloud. | keyword |
| cloud.provider | Name of the cloud provider. | keyword |
| cloud.provider | Name of the cloud provider. Example values are aws, azure, gcp, or digitalocean. | keyword |
| cloud.region | Region in which this host is running. | keyword |
| container.id | Unique container id. | keyword |
| container.image.name | Name of the image the container was built on. | keyword |
Expand All @@ -40,9 +40,12 @@
| destination.as.organization.name | Organization name. | keyword |
| destination.geo.continent_name | Name of the continent. | keyword |
| destination.geo.country_iso_code | Country ISO code. | keyword |
| destination.geo.country_name | Name of the country. | keyword |
| destination.geo.location | Longitude and latitude. | geo_point |
| destination.ip | IP address of the destination. | ip |
| destination.port | Port of the destination. | long |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| event.category | Event category (e.g. database) | keyword |
| event.end | event.end contains the date when the event ended or when the activity was last observed. | date |
| event.kind | Event kind (e.g. event, alert, metric, state, pipeline_error, signal) | keyword |
Expand Down Expand Up @@ -80,6 +83,7 @@
| source.geo.city_name | City name. | keyword |
| source.geo.continent_name | Name of the continent. | keyword |
| source.geo.country_iso_code | Country ISO code. | keyword |
| source.geo.country_name | Name of the country. | keyword |
| source.geo.location | Longitude and latitude. | geo_point |
| source.geo.region_iso_code | Region ISO code. | keyword |
| source.geo.region_name | Region name. | keyword |
Expand Down
1 change: 1 addition & 0 deletions packages/aws/docs/vpn.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,6 +91,7 @@ An example event for `vpn` looks as following:
| data_stream.namespace | Data stream namespace. | constant_keyword |
| data_stream.type | Data stream type. | constant_keyword |
| ecs.version | ECS version this event conforms to. | keyword |
| error.message | Error message. | text |
| host.architecture | Operating system architecture. | keyword |
| host.containerized | If the host is a container. | boolean |
| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword |
Expand Down
10 changes: 10 additions & 0 deletions packages/aws/manifest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -187,6 +187,8 @@ policy_templates:
description: Collect AWS DynamoDB metrics
data_streams:
- dynamodb
categories:
- datastore
inputs:
- type: aws/metrics
title: Collect dynamodb metrics
Expand All @@ -207,6 +209,8 @@ policy_templates:
description: Collect AWS EBS metrics
data_streams:
- ebs
categories:
- datastore
inputs:
- type: aws/metrics
title: Collect EBS metrics
Expand Down Expand Up @@ -346,6 +350,8 @@ policy_templates:
description: Collect AWS RDS metrics
data_streams:
- rds
categories:
- datastore
inputs:
- type: aws/metrics
title: Collect RDS metrics
Expand All @@ -368,6 +374,8 @@ policy_templates:
- s3_daily_storage
- s3_request
- s3access
categories:
- datastore
inputs:
- type: s3
title: Collect S3 access logs
Expand Down Expand Up @@ -511,6 +519,8 @@ policy_templates:
description: Collect AWS VPN metrics
data_streams:
- vpn
categories:
- network
inputs:
- type: aws/metrics
title: Collect VPN metrics
Expand Down