Skip to content

[awslogsencodingextension] Allow CloudTrail logs unmarshaling support for logs received through CloudWatch #45354

@Kavindu-Dodan

Description

@Kavindu-Dodan

Component(s)

extension/encoding/awslogsencoding

Is your feature request related to a problem? Please describe.

CloudTrail logs unmarshaler is currently specialized in handling log payloads arriving from S3. However, AWS officially supports receiving CloudTrail logs through CloudWatch 1. As a user of the awslogsencodingextension component, I would like to get CloudWatch support for CloudTrail logs.

Describe the solution you'd like

As a user of the awslogsencodingextension component, I would like to get CloudWatch support for CloudTrail logs.

Describe alternatives you've considered

No response

Additional context

Consider this VPC flow log discussion - #44710 & AWS Lambda receiver work at #44562 for more context

Tip

React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it. Learn more here.

Footnotes

  1. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-working-with-log-files.html

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions