Filebeat S3 input support for AWS WAF logs (support application/octet-stream)

As of now, there is Filebeat s3 input that doesn't support AWS WAF logs. AWS WAF logs use Kinesis Firehose to get to S3 and the "Content-type" is set to "application/octet-stream". Due to this, the logs didn't get expanded in the Elasticsearch.

If that support can be added it will resolve a big problem and many users looking forward to getting AWS WAF logs to the ELK stack for the analysis.

Thanks in Advance

Hi! Thank you for letting us know! Do you mind opening a github issue for this please? TIA!!

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.