CloudWatch logs in s3

39 views
Skip to first unread message

Aleksandra Błaszczyk

unread,
Jul 24, 2023, 8:39:59 AM7/24/23
to Wazuh mailing list
Hi,
Is it possible to get cloudwatch logs exported into s3, into wazuh? Logs from past few days.

Ive been trying manual was-s3 command. Right now I am getting error "Skipping file with another prefix". Is it possible to point the single file to be imported?

Thanks.

Jeremiah Kolawole

unread,
Jul 24, 2023, 9:47:40 AM7/24/23
to Wazuh mailing list
Hello Aleksandra

It is possible to export CloudWatch logs into S3 and import them into Wazuh. You can check the documentation here to configure s3 bucket and cloudwatch log configuration
 
To resolve the 'Skipping file with another prefix' error, you can specify the exact file you want to import using the 'was-s3' command. Make sure to provide the correct file path and name. 

This issue also details how the same error was resolved.

I hope this helps
Reply all
Reply to author
Forward
0 new messages