Skip to content

Commit 8f1f53e

Browse files
committed
fix mapping error for cloudtrail additonalEventData field
1 parent 1e024a5 commit 8f1f53e

File tree

3 files changed

+5
-2
lines changed

3 files changed

+5
-2
lines changed

CHANGELOG.next.asciidoc

+1
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
6363
- Fix mapping error when zeek weird logs do not contain IP addresses. {pull}15906[15906]
6464
- Improve `elasticsearch/audit` fileset to handle timestamps correctly. {pull}15942[15942]
6565
- Prevent Elasticsearch from spewing log warnings about redundant wildcards when setting up ingest pipelines for the `elasticsearch` module. {issue}15840[15840] {pull}15900[15900]
66+
- Fix mapping error for cloudtrail additionalEventData field {pull}16088[16088]
6667

6768
*Heartbeat*
6869

x-pack/filebeat/module/aws/cloudtrail/ingest/pipeline.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -108,8 +108,8 @@ processors:
108108
- script:
109109
lang: painless
110110
source: |
111-
if (ctx.json.additionalEventdata != null) {
112-
ctx.aws.cloudtrail.additional_eventdata = ctx.json.additionalEventdata.toString();
111+
if (ctx.json.additionalEventData != null) {
112+
ctx.aws.cloudtrail.additional_eventdata = ctx.json.additionalEventData.toString();
113113
}
114114
ignore_failure: true
115115
- rename:

x-pack/filebeat/module/aws/cloudtrail/test/console-login-json.log-expected.json

+2
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
[
22
{
33
"@timestamp": "2014-07-16T15:49:27.000Z",
4+
"aws.cloudtrail.additional_eventdata": "{LoginTo=https://console.aws.amazon.com/s3/, MobileVersion=No, MFAUsed=No}",
45
"aws.cloudtrail.event_version": "1.05",
56
"aws.cloudtrail.response_elements": "{ConsoleLogin=Success}",
67
"aws.cloudtrail.user_identity.arn": "arn:aws:iam::111122223333:user/JohnDoe",
@@ -34,6 +35,7 @@
3435
},
3536
{
3637
"@timestamp": "2014-07-08T17:35:27.000Z",
38+
"aws.cloudtrail.additional_eventdata": "{LoginTo=https://console.aws.amazon.com/sns, MobileVersion=No, MFAUsed=No}",
3739
"aws.cloudtrail.error_message": "Failed authentication",
3840
"aws.cloudtrail.event_version": "1.05",
3941
"aws.cloudtrail.response_elements": "{ConsoleLogin=Failure}",

0 commit comments

Comments
 (0)