Skip to content

[Schema] Update for AWS WAF Integration #198

@Utkarsh-Aga

Description

@Utkarsh-Aga

Currently, when one uses the AWS WAF Integrations, the Index is considered to have the following mapping and the dashboard, visualizations are created based on that.

However, if we check the sample logs of the WAF then it seems to be quite different from the fields defined in the above mapping and fields like httpRequest are not within the aws.waf object. So, if one tries to send the default WAF logs to the OpenSearch, then this native integration cannot be used correctly.

Would like to propose that either an option to define the initial mapping of the Index should be provided [or the mapping should fetched when the Index is selected] or consider updating the schema of the Integration which matches the schema of the default WAF logs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestschemaschema related issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions