AWS CloudWatch Log Reference

Log Samples

Learn what raw CloudWatch events look like before they're processed in Logpoint:

CloudTrail S3 Event (JSON format)

{
  "eventVersion": "1.05",
  "userIdentity": {
    "type": "IAMUser",
    "principalId": "AIDAI3QNMGKROMDBMYFJM",
    "arn": "arn:aws:iam::236512034318:user/abhinit.karna",
    "accountId": "236512034318",
    "accessKeyId": "AKIAJP5S3NGCEP5TVDVQ",
    "userName": "abhinit.karna"
  },
  "eventTime": "2018-12-18T09:45:14Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "HeadObject",
  "awsRegion": "ap-southeast-1",
  "sourceIPAddress": "110.44.116.43",
  "userAgent": "[Boto3/1.4.7 Python/2.7.12 Linux/4.13.0-39-generic Botocore/1.7.28]",
  "requestParameters": {
    "bucketName": "singaporerds-errorlog",
    "key": "mysql-error-running.log.8.log"
  },
  "responseElements": null,
  "additionalEventData": {
    "x-amz-id-2": "jEWOhCzx2xn/XK2dzMJQWrrCj7SG6sFmO2r0Mlw1dagNFFmabcRm0s8/gDNL00H6icCdy2v8ieo="
  },
  "requestID": "461ABC121F4A1350",
  "eventID": "f9aacdb0-c9ce-4064-a4f8-ad9329d1882b",
  "readOnly": true,
  "resources": [
    {
      "type": "AWS::S3::Object",
      "ARN": "arn:aws:s3:::singaporerds-errorlog/mysql-error-running.log.8.log"
    },
    {
      "accountId": "236512034318",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::singaporerds-errorlog"
    }
  ],
  "eventType": "AwsApiCall",
  "recipientAccountId": "236512034318"
}

CloudTrail EC2 Event (JSON format)

Field Mapping

CloudWatch fields are mapped to Logpoint standardized fields for consistent analysis.

Common Field Mappings:

  • eventTimetimestamp

  • eventNameevent_name

  • eventSourcesource

  • sourceIPAddresssource_address

  • userIdentity.userNameuser

  • userIdentity.principalIduser_id

  • awsRegionregion

  • eventTypeevent_type

  • errorCodeerror_code

  • errorMessageerror_message

Last updated

Was this helpful?