# Cloudtrail import on ELK

**URL:** <https://discuss.elastic.co/t/cloudtrail-import-on-elk/141322>\
**Category:** Logstash\
**Created:** [July 24, 2018, 8:04am UTC](https://discuss.elastic.co/t/cloudtrail-import-on-elk/141322 "2018-07-24T08:04:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![moi](https://avatars.discourse-cdn.com/v4/letter/m/c2a13f/32.png) [@moi](https://discuss.elastic.co/u/moi)\
**Post date:** [July 24, 2018, 8:04am UTC](https://discuss.elastic.co/t/cloudtrail-import-on-elk/141322/1 "2018-07-24T08:04:03Z")

</div>

Hi,

This use case is classic I think but I try to import cloudtrail logs from a S3 bucket into a ELK stack but I have this problem : Each logfile is a bunch of events and the "Records" field isn't unserialized and the events not analyzed

I want to use the cloudtrail codec but doesn't seem available and I can't achieve to build it successful, if it's not included on the package maybe there is an another codec for made the job. I tried the codecs "json" and "json\_lines"

My config:

input  
{  
s3 {  
bucket =\> "bucket\_name"  
type =\> "s3\_cloudtrail"  
role\_arn =\> "arn\_role"  
region =\> "eu-west-3"  
interval =\> 120

# codec =\> "json\_lines"

```
	 codec => "json"
} 

```

}

filter {  
json {  
source =\> "Records"  
}  
mutate {  
gsub =\> ["eventSource", ".amazonaws.com$", ""]  
add\_field =\> {  
"document\_id" =\> "%{eventID}"  
}  
}  
}

output  
{

```
elasticsearch
{
    hosts => ["127.0.0.1:9200"]

```

# index =\> "%{[type]}-%{+YYYY.MM.dd}"

```
index => "s3_cloudtrail-%{+YYYY.MM.dd}"
}

```

# stdout { codec =\> rubydebug }

}

- versions :  
root@ip-172-31-15-251:/opt/bitnami# ./logstash/bin/logstash --version  
logstash 6.3.0  
root@ip-172-31-15-251:/opt/bitnami# ./elasticsearch/bin/elasticsearch --version  
Version: 6.3.0, Build: oss/tar/424e937/2018-06-11T23:38:03.357887Z, JVM: 1.8.0\_161  
root@ip-172-31-15-251:/opt/bitnami# ./kibana/bin/kibana --version  
6.3.0

thanks for any guidance, help

---

<div class="post-metadata">

**Author:** ![moi](https://avatars.discourse-cdn.com/v4/letter/m/c2a13f/32.png) [@moi](https://discuss.elastic.co/u/moi)\
**Post date:** [July 25, 2018, 4:36pm UTC](https://discuss.elastic.co/t/cloudtrail-import-on-elk/141322/2 "2018-07-25T16:36:38Z")

</div>

Up please

---

<div class="post-metadata">

**Author:** ![moi](https://avatars.discourse-cdn.com/v4/letter/m/c2a13f/32.png) [@moi](https://discuss.elastic.co/u/moi)\
**Post date:** [August 6, 2018, 8:28am UTC](https://discuss.elastic.co/t/cloudtrail-import-on-elk/141322/3 "2018-08-06T08:28:28Z")

</div>

finally I have compiled the codec "cloudtrail" and now it's fine, the json records are correctly decoded

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2018, 8:28am UTC](https://discuss.elastic.co/t/cloudtrail-import-on-elk/141322/4 "2018-09-03T08:28:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
