You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在SOF-ELK中配置CloudTrail日志JSON全量字段解析的方法

解决SOF-ELK中AWS CloudTrail日志空字段未解析的问题

SOF-ELK默认处理CloudTrail日志时,会跳过空值的errorCode、errorMessage、requestParameters等字段,导致这些字段无法作为独立字段被检索。要实现类似Splunk的全量字段解析,需要调整Logstash过滤规则和Elasticsearch索引模板,具体步骤如下:

1. 修改Logstash CloudTrail过滤配置

找到SOF-ELK的Logstash过滤配置目录(通常为/opt/sof-elk/config/logstash/filters/),编辑对应的CloudTrail过滤文件(比如filter-cloudtrail.conf),添加强制解析空字段的逻辑:

filter {
  if [type] == "cloudtrail" {
    # 解析顶层CloudTrail JSON数据
    json {
      source => "message"
      target => "cloudtrail"
      force_array => false
    }

    # 处理requestParameters:为空时手动生成空对象,确保字段存在
    if [cloudtrail][requestParameters] {
      json {
        source => "[cloudtrail][requestParameters]"
        target => "[cloudtrail][requestParameters]"
      }
    } else {
      mutate {
        add_field => { "[cloudtrail][requestParameters]" => "{}" }
      }
    }

    # 强制保留errorCode和errorMessage字段,空值时设为空字符串
    mutate {
      add_field => {
        "[cloudtrail][errorCode]" => ""
        "[cloudtrail][errorMessage]" => ""
      }
      # 可选:移除原始message字段,减少存储占用
      remove_field => ["message"]
    }
  }
}

关键说明

  • 默认Logstash的json过滤器遇到空值或null时,不会生成对应的字段结构,通过else分支手动添加空对象/空字符串,确保这些字段在所有事件中都存在。
  • force_array => false避免将单个JSON对象解析为数组,符合CloudTrail日志的结构。

2. 调整Elasticsearch索引模板

打开SOF-ELK的Elasticsearch模板目录(通常为/opt/sof-elk/config/elasticsearch/templates/),编辑CloudTrail对应的模板文件(比如cloudtrail.json),添加目标字段的映射规则:

{
  "template": "cloudtrail-*",
  "mappings": {
    "_doc": {
      "properties": {
        "cloudtrail": {
          "properties": {
            "errorCode": { "type": "keyword" },
            "errorMessage": { "type": "text", "fields": { "keyword": { "type": "keyword", "ignore_above": 256 } } },
            "requestParameters": { "type": "object", "dynamic": true }
          }
        }
      }
    }
  }
}

关键说明

  • requestParameters设为object类型并开启dynamic: true,会自动解析其内部的所有子字段,即使不同事件的参数结构不同。
  • errorCode用keyword类型适合精确检索,errorMessage同时配置text和keyword字段,支持全文检索和精确匹配。

3. 生效配置并验证

  • 重启Logstash服务,让新的过滤规则生效:
    sudo systemctl restart logstash
    
  • 等待新的CloudTrail日志进入SOF-ELK后,在Kibana中查看索引的字段列表,确认errorCode、errorMessage、requestParameters已作为独立字段存在,且空值事件也能正常显示这些字段。

内容的提问来源于stack exchange,提问作者Origami

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 07:57:54