log2timeline / plaso

Super timeline all the things
https://plaso.readthedocs.io
Apache License 2.0
1.71k stars 338 forks source link

AWS CloudTrail parser #4182

Open alexgoedeke opened 2 years ago

alexgoedeke commented 2 years ago

Description of problem:

The aws cloud trail log parser does not work with current cloudtrail data.

Source data:

https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-log-file-examples.html

Plaso version:

For example 20220724

jonathan-greig commented 2 years ago

Please see comments on related PR #4187 - This parser is designed for logs saved in JSON-L format.