Hello!
I'm trying to ingest AWS CloudTrail logs via AWS integration in Fleet using S3 input (SQS).
I followed this article to configure CloudTrail logs forwarding to SQS:
https://docs.rapid7.com/insightidr/aws-cloudtrail-sqs/
I've installed integration on Fleet server agent itself and customized configuration like this (Queue URL is 100% correct).
But I'm constantly facing an error:
Message: Failed processing <mark>SQS</mark> message
Error Message:
failed processing SQS message (message will be deleted): non-retryable error: the message is an invalid S3 notification: missing Records field
Stacktrace: github.com/elastic/beats/v7/x-pack/filebeat/input/awss3.(*sqsS3EventProcessor).ProcessSQS
/go/src/github.com/elastic/beats/x-pack/filebeat/input/awss3/sqs_s3_event.go:157
github.com/elastic/beats/v7/x-pack/filebeat/input/awss3.(*sqsReader).Receive.func1
/go/src/github.com/elastic/beats/x-pack/filebeat/input/awss3/sqs.go:91
runtime.goexit
/usr/local/go/src/runtime/asm_amd64.s:1581
Has anyone faced the same issue?
I feel like the issue on Elastic side, not AWS.