Skip to content

API Gateway Layer 7 logs to ECS schema #544

Closed
@Randy-312

Description

@Randy-312

We currently have filebeat sending in Layer7 logs to our ELK stack.
However, we're no longer 'parsing' it out, due to some directional changes to our pre-processing layer, and everything is simply unparsed.

We're going to align to ECS Schema, but need some guidance on Layer7, and if Anyone ELSE is working through this, they may wish to contribute as well.

We can start with Traffic Logging, which is what we have coming in today, and I have solid regex for as well.

Here are my notes so far..

CA has documented some work for what they would do to send to elk.

Here are their fields

And CA's instructions on setup

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions