AWS integration with Collect CloudTrail logs from S3 where SQS queue URL is used.
What did you see?
What did you expect to see?
I expected to be able to search and filter on this field as well as aws.cloudtrail.request_parameters. I am unable to use, for example, ES|QL's DISSECT command because of this.
Anything else?
If I understand correctly, the field size accepted character count just needs increased. Please note that aws.cloudtrail.request_parameters and aws.cloudtrail.response_elements can be very large fields.
Integration Name
AWS [aws]
Dataset Name
aws.cloudtrail
Integration Version
2.23.0
Agent Version
8.14.3
Agent Output Type
elasticsearch
Elasticsearch Version
8.14.1
OS Version and Architecture
Ubuntu 22.04
Software/API Version
No response
Error Message
Ignored Value: The value in this field is too long and cannot be searched or filtered.
Event Original
What did you do?
AWS integration with Collect CloudTrail logs from S3 where SQS queue URL is used.
What did you see?
What did you expect to see?
I expected to be able to search and filter on this field as well as
aws.cloudtrail.request_parameters
. I am unable to use, for example, ES|QL'sDISSECT
command because of this.Anything else?
If I understand correctly, the field size accepted character count just needs increased. Please note that
aws.cloudtrail.request_parameters
andaws.cloudtrail.response_elements
can be very large fields.