aws-samples / siem-on-amazon-opensearch-service

A solution for collecting, correlating and visualizing multiple types of logs to help investigate security incidents.
MIT No Attribution
567 stars 184 forks source link

object mapping for [requestParameters.items] tried to parse field [null] as object, but found a concrete value #367

Closed Yuta-Kuma closed 1 year ago

Yuta-Kuma commented 1 year ago

es-loaderのバージョン2.9.0で発生いたしました。 CloudTrailのログを取り込む際にrequestParameters.itemsが定義されていないためエラーとなっているようです。 eventSource:[dynamodb.amazonaws.com] eventName:PutItem 以下サンプルコードです。

{
    "eventVersion":"1.08",
    "userIdentity":{
        "type":"AssumedRole",
        "principalId":"dummy",
        "arn":"dummy",
        "accountId":"dummy",
        "accessKeyId":"dummy",
        "sessionContext":{
            "sessionIssuer":{
                "type":"Role",
                "principalId":"dummy",
                "arn":"dummy",
                "accountId":"dummy",
                "userName":"dummy"
            },
            "attributes":{
                "creationDate":"2023-04-27T12:18:38Z",
                "mfaAuthenticated":"false"
            }
        }
    },
    "eventTime":"2023-04-27T12:18:38Z",
    "eventSource":"dynamodb.amazonaws.com",
    "eventName":"PutItem",
    "awsRegion":"dummy",
    "sourceIPAddress":"10.0.0.0",
    "userAgent":"dummy",
    "requestParameters":{
        "tableName":"sample","key":{"sample":"dummy"},
        "items":["dummy","sample"]
    },
    "responseElements":null,
    "requestID":"dummy",
    "eventID":"dummy",
    "readOnly":false,
    "resources":[{"accountId":"dummy","type":"AWS::DynamoDB::Table","ARN":"dummy"}],
    "eventType":"AwsApiCall",
    "apiVersion":"2012-08-10",
    "managementEvent":false,
    "recipientAccountId":"dummy",
    "vpcEndpointId":"dummy",
    "eventCategory":"Data",
    "tlsDetails":{
        "tlsVersion":"TLSv1.2",
        "cipherSuite":"dummy",
        "clientProvidedHostHeader":"dynamodb.dummy.amazonaws.com"
    }
}
nakajiak commented 1 year ago

Thanks for the feedback!