I have a bucket that receives all cloudtrail events from multiple accounts.
I have setup notifications from bucket to SNS on ObjectCreate:* and added a subscription from SNS to an SQS queue.
I used "useS3SNS": true on init config. but I get the following error:
Fri Dec 8 16:03:12 2023: Opening event source 'aws_cloudtrail'
Fri Dec 8 16:03:12 2023: Opening 'aws_cloudtrail' source with plugin 'cloudtrail'
Fri Dec 8 16:03:12 2023: An error occurred in an event source, forcing termination...
Fri Dec 8 16:03:12 2023: Closing event source 'aws_cloudtrail'
Events detected: 0
Rule counts by severity:
Triggered rules by rule name:
Error: received SQS message that did not have a Type property
Describe the bug
I have a bucket that receives all cloudtrail events from multiple accounts. I have setup notifications from bucket to SNS on ObjectCreate:* and added a subscription from SNS to an SQS queue.
I used "useS3SNS": true on init config. but I get the following error:
The related helm values.
The SQS messages are like this:
Expected behaviour Parse sqs messages and log files.
Environment