elastic / elastic/integrations

[AWS Cloudtrail]: Drop on aws.cloudtrail.flattened.request_parameters.tags is a concrete value

Open
#15,628 2 comments 0 reactions 0 assignees View on GitHub
Integration:aws needs:triage Team:SDE-Crest Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

AWS [aws]

### Dataset Name

aws.cloudtrail

### Integration Version

3.11.0

### Agent Version

8.15.0

### Agent Output Type

elasticsearch

### Elasticsearch Version

9.0.3

### OS Version and Architecture

Debian x86

### Software/API Version

_No response_

### Error Message

Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Meta:null, Fields:null, Private:interface {}(nil), TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:mapstr.M(nil)}, EncodedEvent:(*elasticsearch.encodedEvent)(0xc008145180)} (status=400): {\"type\":\"document_parsing_exception\",\"reason\":\"[1:1826] object mapping for [aws.cloudtrail.flattened.request_parameters.tags] tried to parse field [tags] as object, but found a concrete value\"}, dropping event!

### Event Original

Not available (it is dropped)

### What did you do?

Connected to a very big cloudtrail, hard to trace source event.
About 27 drops for 1.6 millions event

### What did you see?

Event drop in the agent logs

### What did you expect to see?

No drop

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.