[Asset Inventory POC] Fetch S3 buckets #2045
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary of your changes
Fetch S3 data for the Asset Inventory POC.
Decided to stick to what cloudbeat already fetches. It might change in the future, depending on what product requests.
Known Issues
The Bucket Policy Statement Principal can be a string
"*"
(allows anyone to assume the role) or an object with an specific principal. This is how aws defines it. Because we can't index fields string or object an error is thrown without any mapping. Either saying that can't convert object to string or can't convert string to object.To prevent this, add this index with elastic console:
That will disable indexing of
asset.raw.bucket_policy
. The whole policy will be indexed viaresource_policies
fieldScreenshot/Data
Related Issues