aws-samples / siem-on-amazon-opensearch-service

A solution for collecting, correlating and visualizing multiple types of logs to help investigate security incidents.
MIT No Attribution
567 stars 184 forks source link

illegal_argument_exception on VPCflow log, config and inspector2 logs #366

Closed lafayette-soc closed 1 year ago

lafayette-soc commented 1 year ago

I have received error messages when browsing the VPCflow log, config log, and inpector2 logs.

For Config log the error message is: illegal_argument_exception Field [configuration.AWS:ComplianceItem.Content.Association.InstalledTime] of type [text] does not support custom formats

For inspector log: illegal_argument_exception Field [inspector.firstObservedAt] of type [text] does not support custom formats

For VPCflow log:

illegal_argument_exception at shard 2index log-aws-vpcflowlogs-2023-04node 3psq8gphRJWQqvohDiHoBw

Type illegal_argument_exception Reason Field [end] of type [text] does not support custom formats