CloudTrail Log Collection to Central S3 (Log Archive Account) Is Failing

43 views
Skip to first unread message

Lucas

unread,
Aug 28, 2025, 7:02:52 PM (10 days ago) Aug 28
to Wazuh | Mailing List
Hello

We are collecting CloudTrail logs from multiple AWS accounts (“b”, “c”) into an S3 bucket in the log-archive AWS account “A.”

The S3 bucket structure in the log-archive account is as follows:
<bucket_name>/<organization_id>/AWSLogs/<account_id>/CloudTrail/<region>/<yyyy>/<mm>/<dd>/<file_name>.json.gz

We’ve tried various options in ossec.conf (such as aws_account_id and aws_organization_id, path), but each time we change the settings we encounter different errors, including “Returned exit code 1.”

Best Regards.
Lucas.

Leonardo López

unread,
Aug 28, 2025, 7:45:10 PM (10 days ago) Aug 28
to Wazuh | Mailing List

Lucas

unread,
Aug 29, 2025, 12:22:20 AM (10 days ago) Aug 29
to Wazuh | Mailing List
Hello Leonardo 

I tried applying all the different options from the page you sent and even changed up the combinations, but I still keep getting errors  
Could the issue be that the bucket name doesn’t really look like a typical bucket name?
(The bucket name is: aws-controltower-logs-<Account ID>-ap-northeast-2)
  
Thanks!

2025년 8월 29일 금요일 오전 8시 45분 10초 UTC+9에 Leonardo López님이 작성:

Leonardo López

unread,
Sep 2, 2025, 4:31:36 PM (5 days ago) Sep 2
to Wazuh | Mailing List
Hello Lucas,
I don't think that the issue is the bucket name, but try it if you can.
Can you share the complete wodle configuration?
To check if something is not correct.
Thanks!
Reply all
Reply to author
Forward
0 new messages