Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions packages/aws/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "7.2.1"
changes:
- description: Fix the CloudTrail ingest pipeline failing to extract the session name from `aws.cloudtrail.user_identity.arn` on aws-cn and aws-iso* partitions. The grok pattern `arn:(aws|aws-us-gov)` did not match those partition strings; it is widened to `arn:[a-z0-9-]+`.
type: bugfix
link: https://github.com/elastic/integrations/pull/21179
- version: "7.2.0"
changes:
- description: Remove the external_id variable, its stream template rendering, and the Assume Role with External ID credential option. The CloudFormation trust policy no longer uses an sts:ExternalId condition; Identity Federation now requires only a Role ARN.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1093,7 +1093,7 @@ processors:
- grok:
field: aws.cloudtrail.user_identity.arn
patterns:
- "arn:(aws|aws-us-gov):sts:.*/%{GREEDYDATA:_tmp.session_name}$"
- "arn:[a-z0-9-]+:sts:.*/%{GREEDYDATA:_tmp.session_name}$"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity: 🔵 Low confidence: high path: packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml:1096

No handwritten fixture exercises the widened partition pattern; add an AssumedRole event with an aws-cn (or aws-iso*) sts ARN so the fix is covered by pipeline tests.

Details

The grok pattern now accepts any arn:[a-z0-9-]+:sts: partition, but a grep over the handwritten .log inputs under data_stream/cloudtrail/_dev/test/pipeline/ finds only arn:aws:sts: and arn:aws-us-gov:sts: session ARNs (the latter in test-us-gov-arn.log). The behaviour this PR fixes is therefore never exercised by pipeline tests, so a regression back to the narrower alternation would pass CI unnoticed.

Recommendation:

Add one AssumedRole event with a China-partition session ARN, either appended to an existing multi-line fixture such as test-assume-role-json.log or as a small new fixture alongside test-us-gov-arn.log, so related.user receives the session name; then regenerate expected output with elastic-package test pipeline -g. Example record:

{"eventVersion":"1.08","userIdentity":{"type":"AssumedRole","principalId":"AROAEXAMPLEID:cn-session","arn":"arn:aws-cn:sts::123456789012:assumed-role/ExampleRole/cn-session","accountId":"123456789012","sessionContext":{"sessionIssuer":{"type":"Role","principalId":"AROAEXAMPLEID","arn":"arn:aws-cn:iam::123456789012:role/ExampleRole","accountId":"123456789012","userName":"ExampleRole"}}},"eventTime":"2024-01-01T00:00:00Z","eventSource":"sts.amazonaws.com","eventName":"GetCallerIdentity","awsRegion":"cn-north-1","sourceIPAddress":"192.0.2.10","userAgent":"aws-cli/2.0","eventType":"AwsApiCall","recipientAccountId":"123456789012"}

🤖 AI-Generated Review | Vera Review Bot - v0.4.1 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

ignore_missing: true
if: (ctx.aws?.cloudtrail?.user_identity?.type == 'AssumedRole' || ctx.aws?.cloudtrail?.user_identity?.type == 'FederatedUser') && ctx.aws?.cloudtrail?.user_identity?.arn != null
tag: extract_session_name_from_arn
Expand Down
2 changes: 1 addition & 1 deletion packages/aws/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 3.6.1
name: aws
title: AWS
version: 7.2.0
version: 7.2.1
description: Collect logs and metrics from Amazon Web Services (AWS) with Elastic Agent.
type: integration
categories:
Expand Down
Loading