@@ -33,7 +33,7 @@ Example config:
3333[source,yaml]
3434----
3535- module: aws
36- s3access :
36+ cloudtrail :
3737 enabled: false
3838 #var.queue_url: https://sqs.myregion.amazonaws.com/123456/myqueue
3939 #var.shared_credential_file: /etc/filebeat/aws_credentials
@@ -42,50 +42,51 @@ Example config:
4242 #var.api_timeout: 120s
4343 #var.endpoint: amazonaws.com
4444
45- elb :
45+ cloudwatch :
4646 enabled: false
47-
48- # AWS SQS queue url
4947 #var.queue_url: https://sqs.myregion.amazonaws.com/123456/myqueue
48+ #var.shared_credential_file: /etc/filebeat/aws_credentials
49+ #var.credential_profile_name: fb-aws
50+ #var.visibility_timeout: 300s
51+ #var.api_timeout: 120s
52+ #var.endpoint: amazonaws.com
5053
51- # Filename of AWS credential file
52- # If not set "$HOME/.aws/credentials" is used on Linux/Mac
53- # "%UserProfile%\.aws\credentials" is used on Windows
54- # var.shared_credential_file: /etc/filebeat/aws_credentials
55-
56- # Profile name for aws credential
57- # If not set the default profile is used
58- # var.credential_profile_name: fb-aws
59-
60- vpcflow:
54+ ec2:
6155 enabled: false
62-
63- # AWS SQS queue url
6456 #var.queue_url: https://sqs.myregion.amazonaws.com/123456/myqueue
57+ #var.shared_credential_file: /etc/filebeat/aws_credentials
58+ #var.credential_profile_name: fb-aws
59+ #var.visibility_timeout: 300s
60+ #var.api_timeout: 120s
61+ #var.endpoint: amazonaws.com
6562
66- # Filename of AWS credential file
67- # If not set "$HOME/.aws/credentials" is used on Linux/Mac
68- # "%UserProfile%\.aws\credentials" is used on Windows
69- # var.shared_credential_file: /etc/filebeat/aws_credentials
70-
71- # Profile name for aws credential
72- # If not set the default profile is used
73- # var.credential_profile_name: fb-aws
74-
75- cloudtrail:
63+ elb:
7664 enabled: false
65+ #var.queue_url: https://sqs.myregion.amazonaws.com/123456/myqueue
66+ #var.shared_credential_file: /etc/filebeat/aws_credentials
67+ #var.credential_profile_name: fb-aws
68+ #var.visibility_timeout: 300s
69+ #var.api_timeout: 120s
70+ #var.endpoint: amazonaws.com
7771
78- # AWS SQS queue url
72+ s3access:
73+ enabled: false
7974 #var.queue_url: https://sqs.myregion.amazonaws.com/123456/myqueue
75+ #var.shared_credential_file: /etc/filebeat/aws_credentials
76+ #var.credential_profile_name: fb-aws
77+ #var.visibility_timeout: 300s
78+ #var.api_timeout: 120s
79+ #var.endpoint: amazonaws.com
8080
81- # Filename of AWS credential file
82- # If not set "$HOME/.aws/credentials" is used on Linux/Mac
83- # "%UserProfile%\.aws\credentials" is used on Windows
84- # var.shared_credential_file: /etc/filebeat/aws_credentials
81+ vpcflow:
82+ enabled: false
83+ #var.queue_url: https://sqs.myregion.amazonaws.com/123456/myqueue
84+ #var.shared_credential_file: /etc/filebeat/aws_credentials
85+ #var.credential_profile_name: fb-aws
86+ #var.visibility_timeout: 300s
87+ #var.api_timeout: 120s
88+ #var.endpoint: amazonaws.com
8589
86- # Profile name for aws credential
87- # If not set the default profile is used
88- # var.credential_profile_name: fb-aws
8990----
9091
9192*`var.queue_url`*::
@@ -122,6 +123,22 @@ The `cloudtrail` fileset does not read the CloudTrail Digest files
122123that are delivered to the S3 bucket when Log File Integrity is turned
123124on, it only reads the CloudTrail logs.
124125
126+ [float]
127+ === cloudwatch fileset
128+
129+ Users can use Amazon CloudWatch Logs to monitor, store, and access log files
130+ from different sources. Export logs from log groups to an Amazon S3 bucket which
131+ has SQS notification setup already. This fileset will parse these logs into
132+ `timestamp` and `message` field.
133+
134+ [float]
135+ === ec2 fileset
136+
137+ This fileset is specifically for EC2 logs stored in AWS CloudWatch. Export logs
138+ from log groups to Amazon S3 bucket which has SQS notification setup already.
139+ With this fileset, EC2 logs will be parsed into fields like `ip`
140+ and `program_name`. For logs from other services, please use `cloudwatch` fileset.
141+
125142[float]
126143=== elb fileset
127144
0 commit comments