diff --git a/packages/aws/changelog.yml b/packages/aws/changelog.yml index 687c1f92318..be3ae8a3581 100644 --- a/packages/aws/changelog.yml +++ b/packages/aws/changelog.yml @@ -1,4 +1,9 @@ # newer versions go on top +- version: "7.0.1" + changes: + - description: Fix the CloudTrail ingest pipeline failing to extract the session name from `aws.cloudtrail.user_identity.arn` on aws-cn and aws-iso* partitions. The grok pattern `arn:(aws|aws-us-gov)` did not match those partition strings; it is widened to `arn:[a-z0-9-]+`. + type: bugfix + link: https://github.com/elastic/integrations/pull/21178 - version: "7.0.0" changes: - description: Hide the CloudWatch, EBS, EC2, ECS, and S3 metric/log inputs when the Identity Federation setup access option is selected, since only the GuardDuty API input supports identity federation. diff --git a/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml b/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml index 4b66511f2b8..4eed65a777a 100644 --- a/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml +++ b/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml @@ -1086,7 +1086,7 @@ processors: - grok: field: aws.cloudtrail.user_identity.arn patterns: - - "arn:(aws|aws-us-gov):sts:.*/%{GREEDYDATA:user.changes.name}$" + - "arn:[a-z0-9-]+:sts:.*/%{GREEDYDATA:user.changes.name}$" ignore_missing: true if: (ctx.aws?.cloudtrail?.user_identity?.type == 'AssumedRole' || ctx.aws?.cloudtrail?.user_identity?.type == 'FederatedUser') && ctx.aws?.cloudtrail?.user_identity?.arn != null tag: extract_user_name_from_arn diff --git a/packages/aws/manifest.yml b/packages/aws/manifest.yml index 5bbad6ee374..82d8c9889c2 100644 --- a/packages/aws/manifest.yml +++ b/packages/aws/manifest.yml @@ -1,7 +1,7 @@ format_version: 3.6.1 name: aws title: AWS -version: 7.0.0 +version: 7.0.1 description: Collect logs and metrics from Amazon Web Services (AWS) with Elastic Agent. type: integration categories: