From bf4c26409f8d025ecc09d8a03ff7cab40d4e746b Mon Sep 17 00:00:00 2001 From: Dan Kortschak Date: Thu, 10 Sep 2026 08:52:56 +0930 Subject: [PATCH 1/2] aws.cloudtrail: widen ARN partition grok pattern to include aws-cn and aws-iso* The grok pattern used to extract the session name from aws.cloudtrail.user_identity.arn matched only arn:aws:... and arn:aws-us-gov:... partitions. Identities from aws-cn and aws-iso* partitions were silently ignored, leaving user.changes.name unpopulated. Widening the character class from (aws|aws-us-gov) to [a-z0-9-] covers all current and future AWS partition strings without requiring updates for new partition names. Co-Authored-By: Claude Sonnet 4.6 --- packages/aws/changelog.yml | 5 +++++ .../cloudtrail/elasticsearch/ingest_pipeline/default.yml | 2 +- packages/aws/manifest.yml | 2 +- 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/packages/aws/changelog.yml b/packages/aws/changelog.yml index bfb3594ebd4..27c444bfc62 100644 --- a/packages/aws/changelog.yml +++ b/packages/aws/changelog.yml @@ -1,4 +1,9 @@ # newer versions go on top +- version: "7.2.1" + changes: + - description: Fix the CloudTrail ingest pipeline failing to extract the session name from `aws.cloudtrail.user_identity.arn` on aws-cn and aws-iso* partitions. The grok pattern `arn:(aws|aws-us-gov)` did not match those partition strings; it is widened to `arn:[a-z0-9-]+`. + type: bugfix + link: https://github.com/elastic/integrations/pull/21162 - version: "7.2.0" changes: - description: Remove the external_id variable, its stream template rendering, and the Assume Role with External ID credential option. The CloudFormation trust policy no longer uses an sts:ExternalId condition; Identity Federation now requires only a Role ARN. diff --git a/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml b/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml index 2a20d26a24d..a6ee7ddcde2 100644 --- a/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml +++ b/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml @@ -1093,7 +1093,7 @@ processors: - grok: field: aws.cloudtrail.user_identity.arn patterns: - - "arn:(aws|aws-us-gov):sts:.*/%{GREEDYDATA:_tmp.session_name}$" + - "arn:[a-z0-9-]+:sts:.*/%{GREEDYDATA:_tmp.session_name}$" ignore_missing: true if: (ctx.aws?.cloudtrail?.user_identity?.type == 'AssumedRole' || ctx.aws?.cloudtrail?.user_identity?.type == 'FederatedUser') && ctx.aws?.cloudtrail?.user_identity?.arn != null tag: extract_session_name_from_arn diff --git a/packages/aws/manifest.yml b/packages/aws/manifest.yml index fc6699a5bd3..72a2693a586 100644 --- a/packages/aws/manifest.yml +++ b/packages/aws/manifest.yml @@ -1,7 +1,7 @@ format_version: 3.6.1 name: aws title: AWS -version: 7.2.0 +version: 7.2.1 description: Collect logs and metrics from Amazon Web Services (AWS) with Elastic Agent. type: integration categories: From f7c70dc2bfb07a0c437d7efc4717b51636c47e16 Mon Sep 17 00:00:00 2001 From: Dan Kortschak Date: Fri, 11 Sep 2026 06:07:48 +0930 Subject: [PATCH 2/2] aws.cloudtrail: fix changelog PR link --- packages/aws/changelog.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/aws/changelog.yml b/packages/aws/changelog.yml index 27c444bfc62..a5931c72306 100644 --- a/packages/aws/changelog.yml +++ b/packages/aws/changelog.yml @@ -3,7 +3,7 @@ changes: - description: Fix the CloudTrail ingest pipeline failing to extract the session name from `aws.cloudtrail.user_identity.arn` on aws-cn and aws-iso* partitions. The grok pattern `arn:(aws|aws-us-gov)` did not match those partition strings; it is widened to `arn:[a-z0-9-]+`. type: bugfix - link: https://github.com/elastic/integrations/pull/21162 + link: https://github.com/elastic/integrations/pull/21179 - version: "7.2.0" changes: - description: Remove the external_id variable, its stream template rendering, and the Assume Role with External ID credential option. The CloudFormation trust policy no longer uses an sts:ExternalId condition; Identity Federation now requires only a Role ARN.