<wodle name="aws-s3">
<disabled>no</disabled>
<interval>10m</interval>
<run_on_start>no</run_on_start>
<skip_on_error>no</skip_on_error>
<bucket type="cloudtrail">
<name>my-wazuh-cloudtrail</name>
<access_key>SECRET</access_key>
<secret_key>SECRET</secret_key>
<remove_from_bucket>yes</remove_from_bucket>
</bucket>
</wodle>
<wodle name="aws-s3">
<disabled>no</disabled>
<interval>10m</interval>
<run_on_start>no</run_on_start>
<skip_on_error>no</skip_on_error>
<remove_from_bucket>yes</remove_from_bucket>
<bucket type="cloudtrail">
<name>my-wazuh-cloudtrail</name>
<access_key>SECRET</access_key>
<secret_key>SECRET</secret_key>
</bucket>
</wodle>2018/10/09 09:17:19 wazuh-modulesd:aws-s3: INFO: Starting fetching of logs.2018/10/09 09:17:19 wazuh-modulesd:aws-s3: INFO: Executing Bucket Analisys: sbg-wazuh-cloudtrail2018/10/09 09:17:24 wazuh-modulesd:aws-s3: INFO: Fetching logs finished.--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/68b3e42c-efb8-4602-aa0d-36e1662bc54b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
2018/10/10 09:48:02 wazuh-modulesd:aws-s3: DEBUG: Found a bucket tag2018/10/10 09:48:02 wazuh-modulesd:aws-s3: DEBUG: Creating first bucket structure2018/10/10 09:48:02 wazuh-modulesd:aws-s3: DEBUG: Loop thru child nodes2018/10/10 09:48:02 wazuh-modulesd:aws-s3: DEBUG: Parse child node: name2018/10/10 09:48:02 wazuh-modulesd:aws-s3: DEBUG: Parse child node: access_key2018/10/10 09:48:02 wazuh-modulesd:aws-s3: DEBUG: Parse child node: secret_key2018/10/10 09:48:02 wazuh-modulesd:aws-s3: INFO: Module AWS started2018/10/10 09:48:02 wazuh-modulesd:aws-s3: INFO: Waiting interval to start fetching.2018/10/10 09:57:19 wazuh-modulesd:aws-s3: INFO: Starting fetching of logs.2018/10/10 09:57:19 wazuh-modulesd:aws-s3: INFO: Executing Bucket Analisys: my-cloud-wazuh-cloudtrail2018/10/10 09:57:19 wazuh-modulesd:aws-s3: DEBUG: Create argument list2018/10/10 09:57:19 wazuh-modulesd:aws-s3: DEBUG: Launching S3 Command: /var/ossec/wodles/aws/aws-s3 --bucket my-cloud-wazuh-cloudtrail --access_key SECRET --secret_key SECRET --type cloudtrail --debug 22018/10/10 09:57:21 wazuh-modulesd:aws-s3: DEBUG: Bucket: - OUTPUT: DEBUG: Args: ['/var/ossec/wodles/aws/aws-s3', '--bucket', 'my-cloud-wazuh-cloudtrail', '--access_key', 'SECRET', '--secret_key', 'SECRET', '--type', 'cloudtrail', '--debug', '2']2018/10/10 09:57:28 wazuh-modulesd:aws-s3: INFO: Fetching logs finished.2018/10/10 10:07:19 wazuh-modulesd:aws-s3: INFO: Starting fetching of logs.2018/10/10 10:07:19 wazuh-modulesd:aws-s3: INFO: Executing Bucket Analisys: my-cloud-wazuh-cloudtrail2018/10/10 10:07:19 wazuh-modulesd:aws-s3: DEBUG: Create argument list2018/10/10 10:07:19 wazuh-modulesd:aws-s3: DEBUG: Launching S3 Command: /var/ossec/wodles/aws/aws-s3 --bucket my-cloud-wazuh-cloudtrail --access_key SECRET --secret_key SECRET --type cloudtrail --debug 22018/10/10 10:07:21 wazuh-modulesd:aws-s3: DEBUG: Bucket: - OUTPUT: DEBUG: Args: ['/var/ossec/wodles/aws/aws-s3', '--bucket', 'my-cloud-wazuh-cloudtrail', '--access_key', 'SECRET', '--secret_key', 'SECRET', '--type', 'cloudtrail', '--debug', '2']2018/10/10 10:07:29 wazuh-modulesd:aws-s3: INFO: Fetching logs finished.DEBUG: +++ Working on ACCOUNT_ID - us-west-1DEBUG: +++ Marker: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10DEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0005Z_SXB3Qj4faWzx0rHY.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0035Z_en2FNSb8QlVQgXvm.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0105Z_meAZIXf9FMn1cX1P.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0135Z_KXswyBPmMlhpw9bl.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0205Z_woto1LZDlqIln9Ri.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0235Z_zTioCj2LQfadWCQj.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0305Z_vB5j3ASy2yKR74Xi.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0335Z_6lZhh4fQsTd5kHBn.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0405Z_2F4QTQW2HFHPJfzh.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0435Z_GAEMYZSGYJFO5ouy.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0505Z_rzkli0DpPhHqC0K6.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0535Z_CXOtbbCzY3jEl4ro.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0605Z_Vb3nyMWgTFVlG90J.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0635Z_qEF8D6bvCwn3ekbB.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0705Z_fua8sHC5iYpLJSjx.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0720Z_3zch5ZCRZ2af2PqM.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0720Z_OhVhZ6dYUwKIVv5D.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0735Z_CmS4NUDviwAymCRL.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0805Z_65AXfLHaOVJlBJko.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0835Z_09aW368IRgjO60zJ.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0905Z_VBqZx7HXWkekMcjQ.json.gzDEBUG: ++ Skipping previously processed file: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T0935Z_C0CEC4Al4uqJXzxe.json.gzDEBUG: ++ Found new log: AWSLogs/ACCOUNT_ID/CloudTrail/us-west-1/2018/10/10/ACCOUNT_ID_CloudTrail_us-west-1_20181010T1005Z_w73Ao5azNhuJO2yX.json.gz--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/3eca3d5d-668f-4085-a3d4-3a5a6cce7e5f%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.