Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please add AWS Config Logs to this plugin #20

Open
wrsuarez opened this issue Nov 4, 2016 · 5 comments
Open

Please add AWS Config Logs to this plugin #20

wrsuarez opened this issue Nov 4, 2016 · 5 comments

Comments

@wrsuarez
Copy link

wrsuarez commented Nov 4, 2016

This is one of the key gaps between this and Splunk AWS app at the moment. Config log data follows the exact process as CloudTrail and I've gotten as far as launching a new input in Graylog that is correctly receiving notifications when new Config items arrive but obviously the data structure and elements are different between CloudTrail and Config so the plug in exceptions out when it sees fields that it doesn't have a variable for.

@lennartkoopmann lennartkoopmann added this to the 1.3.0 milestone Nov 6, 2016
@baldzern4
Copy link
Contributor

Hi,
👍 for this. We see a lot of exceptions in our graylog. Also the cloudtrail SQS queue is filling up with AWS config messages which can not be fetched by the plugin.
Any ideas when this is being included?

@bernd bernd modified the milestone: 1.3.0 Jul 26, 2017
@bernd bernd added the feature label Jul 26, 2017
@dennisoelkers
Copy link
Member

Since the last release we are supporting Cloudtrail in this plugin. Can you please verify if you are still unable to solve your issue?

@arunmat
Copy link

arunmat commented Feb 14, 2018

@dennisoelkers, they are referring to support AWS config logs.

@badllama
Copy link

Has there been any progress with supporting AWS Config data with this (or some other) plugin?

@danotorrey
Copy link
Contributor

danotorrey commented Aug 21, 2018

AWS Config tracks AWS environment changes based on user-defined/focused compliance rules (eg. if ports on a security group changed, then move security group to Not Compliant state - which also triggers a SNS message as an alert of the change). I believe this request is asking for the ability to push the AWS Config SNS message content to Graylog (which might allow more focused logging than CloudTrail).

Appears to be related to #18 sns events to graylog

@danotorrey danotorrey changed the title Please add AWS Config Logs to this plug in Please add AWS Config Logs to this plugin Sep 14, 2018
@no-response no-response bot closed this as completed Nov 5, 2018
@Graylog2 Graylog2 deleted a comment from no-response bot Nov 5, 2018
@dennisoelkers dennisoelkers reopened this Nov 5, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

8 participants