wazuh-dashboard-plugins
wazuh-dashboard-plugins copied to clipboard
Amazon AWS dashboard not showing information in some graphs
Wazuh | Elastic | Rev | Security |
---|---|---|---|
4.3 | 7.10.2 | 4301-1 | ODFE |
Browser |
---|
Chrome, Firefox, Safari, etc |
Description The AWS module shows "No results found" for both the Accounts and Regions sections. I'm not sure if this is a bug because Cloudtrail is the only integration I enabled in this case.
Preconditions N/A
Steps to reproduce
- Enable the Cloudtrail integration in Wazuh (instructions).
- Go to the Amazon AWS module in the Wazuh APP.
Expected Result All graphs inside the module should show any information.
Actual Result
All graphs show information, except for Regions
and Accounts
which say: No results found
Screenshots
Additional context
The alerts that were generated do contain fields for Regions and Accounts but then they are not displayed on the dashboard.
Hi Team,
Any updates on timeline for the fix of this issue ?
It would be great to have this issue fixed because the dashboards currently are not able display AWS Account IDs from cloudTrail logs. Even with logs from many different aws account IDs, the accounts
as well as regions
spaces in the AWS Dashboards remain empty.
It would be really great if this is fixed at the earliest. Looking forward to it. Thanks.
Related issues
- #2004
- #2260
- https://github.com/wazuh/wazuh/pull/4459
We tested the PR https://github.com/wazuh/wazuh/pull/4459 and confirmed that adding these mappings results in a transformation of fields from aws.awsRegion
to aws.region
, so the Dashboards are rendering the results properly now.
In order to test this, we configured the AWS module, as defined in the step nr.1 of this issue, and then, appending AWS logs to the alerts.json
file.
- [x] We need to test if this continues to work in a fresh environment, as we used the [Elastic API]
(https://www.elastic.co/guide/en/elasticsearch/reference/7.10/set-processor.html) to update the ingest pipelines with the new mappings.
For this, we need to build a development environment using this Wazuh branch: 3.11-update-filebeat-module, which is linked in the PR listed above.
Task: test in a fresh environment
Tested PR https://github.com/wazuh/wazuh/pull/4459 in a fresh environment.