{"id":41023,"date":"2023-09-08T22:50:15","date_gmt":"2022-12-27T06:41:41","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/"},"modified":"2024-04-30T22:02:47","modified_gmt":"2024-04-30T14:02:47","slug":"%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/","title":{"rendered":"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch"},"content":{"rendered":"<h1>\u9996\u5148<\/h1>\n<p>\u6211\u89c9\u5f97\u628aCloudtrail\u65e5\u5fd7\u653e\u5165\u53ef\u4ee5\u4f7f\u7528Kibana\u7684Elasticsearch\u4e2d\u8fdb\u884c\u5206\u6790\u4f1a\u5f88\u65b9\u4fbf\uff0c\u6240\u4ee5\u53c2\u8003\u4e86\u8fd9\u4e2a\u5e76\u5c1d\u8bd5\u521b\u5efa\u4e86Lambda\u51fd\u6570\u7684\u793a\u4f8b\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442237434c4406c9e49f\/2-0.png\" alt=\"SnapCrab_NoName_2015-2-21_23-17-16_No-00.png\" \/><\/div>\n<p>\u8fd9\u91cc\u662f\u521b\u5efa\u7684 Lambda \u51fd\u6570\u7684\u4ee3\u7801\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"kd\">var<\/span> <span class=\"nx\">aws<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">require<\/span><span class=\"p\">(<\/span><span class=\"dl\">'<\/span><span class=\"s1\">aws-sdk<\/span><span class=\"dl\">'<\/span><span class=\"p\">);<\/span>\r\n<span class=\"kd\">var<\/span> <span class=\"nx\">zlib<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">require<\/span><span class=\"p\">(<\/span><span class=\"dl\">'<\/span><span class=\"s1\">zlib<\/span><span class=\"dl\">'<\/span><span class=\"p\">);<\/span>\r\n<span class=\"kd\">var<\/span> <span class=\"nx\">elasticsearch<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">require<\/span><span class=\"p\">(<\/span><span class=\"dl\">'<\/span><span class=\"s1\">elasticsearch<\/span><span class=\"dl\">'<\/span><span class=\"p\">);<\/span>\r\n\r\n<span class=\"kd\">var<\/span> <span class=\"nx\">ES_INDEX<\/span> <span class=\"o\">=<\/span> <span class=\"dl\">'<\/span><span class=\"s1\">cloudtrail<\/span><span class=\"dl\">'<\/span><span class=\"p\">;<\/span> <span class=\"c1\">\/\/ Elasticsearch index name<\/span>\r\n<span class=\"kd\">var<\/span> <span class=\"nx\">ES_TYPE<\/span> <span class=\"o\">=<\/span> <span class=\"dl\">'<\/span><span class=\"s1\">log<\/span><span class=\"dl\">'<\/span><span class=\"p\">;<\/span> <span class=\"c1\">\/\/ Elsticsearch index type name<\/span>\r\n<span class=\"kd\">var<\/span> <span class=\"nx\">ES_CLIENT<\/span> <span class=\"o\">=<\/span> <span class=\"k\">new<\/span> <span class=\"nx\">elasticsearch<\/span><span class=\"p\">.<\/span><span class=\"nx\">Client<\/span><span class=\"p\">({<\/span>\r\n    <span class=\"na\">host<\/span><span class=\"p\">:<\/span> <span class=\"dl\">'<\/span><span class=\"s1\">&lt;ELASTICSEARCH_URL:PORT_NUMBER&gt;<\/span><span class=\"dl\">'<\/span> <span class=\"c1\">\/\/Elasticsearch URL:port<\/span>\r\n<span class=\"p\">});<\/span> \r\n\r\n<span class=\"c1\">\/\/start lambda function<\/span>\r\n<span class=\"nx\">exports<\/span><span class=\"p\">.<\/span><span class=\"nx\">handler<\/span> <span class=\"o\">=<\/span> <span class=\"kd\">function<\/span><span class=\"p\">(<\/span><span class=\"nx\">event<\/span><span class=\"p\">,<\/span> <span class=\"nx\">context<\/span><span class=\"p\">)<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">console<\/span><span class=\"p\">.<\/span><span class=\"nx\">log<\/span><span class=\"p\">(<\/span><span class=\"dl\">'<\/span><span class=\"s1\">Received event:<\/span><span class=\"dl\">'<\/span><span class=\"p\">);<\/span>\r\n    <span class=\"kd\">var<\/span> <span class=\"nx\">bucket<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">event<\/span><span class=\"p\">.<\/span><span class=\"nx\">Records<\/span><span class=\"p\">[<\/span><span class=\"mi\">0<\/span><span class=\"p\">].<\/span><span class=\"nx\">s3<\/span><span class=\"p\">.<\/span><span class=\"nx\">bucket<\/span><span class=\"p\">.<\/span><span class=\"nx\">name<\/span><span class=\"p\">;<\/span>\r\n    <span class=\"kd\">var<\/span> <span class=\"nx\">key<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">event<\/span><span class=\"p\">.<\/span><span class=\"nx\">Records<\/span><span class=\"p\">[<\/span><span class=\"mi\">0<\/span><span class=\"p\">].<\/span><span class=\"nx\">s3<\/span><span class=\"p\">.<\/span><span class=\"nx\">object<\/span><span class=\"p\">.<\/span><span class=\"nx\">key<\/span><span class=\"p\">;<\/span>\r\n    <span class=\"kd\">var<\/span> <span class=\"nx\">region<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">event<\/span><span class=\"p\">.<\/span><span class=\"nx\">Records<\/span><span class=\"p\">[<\/span><span class=\"mi\">0<\/span><span class=\"p\">].<\/span><span class=\"nx\">awsRegion<\/span><span class=\"p\">;<\/span>\r\n    <span class=\"kd\">var<\/span> <span class=\"nx\">s3<\/span> <span class=\"o\">=<\/span> <span class=\"k\">new<\/span> <span class=\"nx\">aws<\/span><span class=\"p\">.<\/span><span class=\"nx\">S3<\/span><span class=\"p\">({<\/span>\r\n        <span class=\"na\">apiVersion<\/span><span class=\"p\">:<\/span> <span class=\"dl\">'<\/span><span class=\"s1\">2006-03-01<\/span><span class=\"dl\">'<\/span><span class=\"p\">,<\/span>\r\n        <span class=\"na\">region<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">region<\/span>\r\n    <span class=\"p\">});<\/span>\r\n\r\n    <span class=\"nx\">s3<\/span><span class=\"p\">.<\/span><span class=\"nx\">getObject<\/span><span class=\"p\">({<\/span>\r\n        <span class=\"na\">Bucket<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">bucket<\/span><span class=\"p\">,<\/span>\r\n        <span class=\"na\">Key<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">key<\/span>\r\n    <span class=\"p\">},<\/span> <span class=\"kd\">function<\/span><span class=\"p\">(<\/span><span class=\"nx\">err<\/span><span class=\"p\">,<\/span><span class=\"nx\">data<\/span><span class=\"p\">)<\/span> <span class=\"p\">{<\/span>\r\n        <span class=\"k\">if<\/span><span class=\"p\">(<\/span><span class=\"nx\">err<\/span><span class=\"p\">){<\/span>\r\n            <span class=\"nx\">context<\/span><span class=\"p\">.<\/span><span class=\"nx\">done<\/span><span class=\"p\">(<\/span><span class=\"dl\">'<\/span><span class=\"s1\">error<\/span><span class=\"dl\">'<\/span><span class=\"p\">,<\/span><span class=\"dl\">'<\/span><span class=\"s1\">error getting file<\/span><span class=\"dl\">'<\/span> <span class=\"o\">+<\/span> <span class=\"nx\">err<\/span><span class=\"p\">);<\/span>\r\n        <span class=\"p\">}<\/span> <span class=\"k\">else<\/span> <span class=\"p\">{<\/span>\r\n            <span class=\"kd\">var<\/span> <span class=\"nx\">contentType<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">data<\/span><span class=\"p\">.<\/span><span class=\"nx\">ContentType<\/span><span class=\"p\">;<\/span>\r\n            <span class=\"kd\">var<\/span> <span class=\"nx\">contentEncoding<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">data<\/span><span class=\"p\">.<\/span><span class=\"nx\">ContentEncoding<\/span><span class=\"p\">;<\/span>\r\n            <span class=\"k\">if<\/span> <span class=\"p\">(<\/span><span class=\"nx\">contentType<\/span> <span class=\"o\">===<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">application\/json<\/span><span class=\"dl\">\"<\/span>\r\n                <span class=\"o\">&amp;&amp;<\/span> <span class=\"nx\">contentEncoding<\/span> <span class=\"o\">===<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">gzip<\/span><span class=\"dl\">\"<\/span><span class=\"p\">)<\/span> <span class=\"p\">{<\/span>\r\n                <span class=\"kd\">var<\/span> <span class=\"nx\">logFileName<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">key<\/span><span class=\"p\">.<\/span><span class=\"nx\">substr<\/span><span class=\"p\">(<\/span><span class=\"nx\">key<\/span><span class=\"p\">.<\/span><span class=\"nx\">lastIndexOf<\/span><span class=\"p\">(<\/span><span class=\"dl\">\"<\/span><span class=\"s2\">\/<\/span><span class=\"dl\">\"<\/span><span class=\"p\">)<\/span> <span class=\"o\">+<\/span> <span class=\"mi\">1<\/span><span class=\"p\">);<\/span>\r\n                <span class=\"kd\">var<\/span> <span class=\"nx\">buf<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">data<\/span><span class=\"p\">.<\/span><span class=\"nx\">Body<\/span><span class=\"p\">;<\/span>\r\n                <span class=\"nx\">zlib<\/span><span class=\"p\">.<\/span><span class=\"nx\">gunzip<\/span><span class=\"p\">(<\/span><span class=\"nx\">buf<\/span><span class=\"p\">,<\/span> <span class=\"kd\">function<\/span><span class=\"p\">(<\/span><span class=\"nx\">_<\/span><span class=\"p\">,<\/span> <span class=\"nx\">dezipped<\/span><span class=\"p\">)<\/span> <span class=\"p\">{<\/span>\r\n                    <span class=\"kd\">var<\/span> <span class=\"nx\">json<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">JSON<\/span><span class=\"p\">.<\/span><span class=\"nx\">parse<\/span><span class=\"p\">(<\/span><span class=\"nx\">dezipped<\/span><span class=\"p\">.<\/span><span class=\"nx\">toString<\/span><span class=\"p\">(<\/span><span class=\"dl\">'<\/span><span class=\"s1\">utf-8<\/span><span class=\"dl\">'<\/span><span class=\"p\">));<\/span>\r\n                    <span class=\"nx\">sendToES<\/span><span class=\"p\">(<\/span><span class=\"nx\">context<\/span><span class=\"p\">,<\/span><span class=\"nx\">region<\/span><span class=\"p\">,<\/span><span class=\"nx\">logFileName<\/span><span class=\"p\">,<\/span><span class=\"nx\">json<\/span><span class=\"p\">);<\/span>\r\n                <span class=\"p\">});<\/span>\r\n            <span class=\"p\">}<\/span>\r\n        <span class=\"p\">}<\/span>\r\n    <span class=\"p\">});<\/span>\r\n<span class=\"p\">};<\/span>\r\n\r\n<span class=\"c1\">\/\/bulk send to Elasticsearch<\/span>\r\n<span class=\"kd\">function<\/span> <span class=\"nx\">sendToES<\/span><span class=\"p\">(<\/span><span class=\"nx\">context<\/span><span class=\"p\">,<\/span><span class=\"nx\">region<\/span><span class=\"p\">,<\/span><span class=\"nx\">logFileName<\/span><span class=\"p\">,<\/span><span class=\"nx\">json<\/span><span class=\"p\">){<\/span>\r\n    <span class=\"kd\">var<\/span> <span class=\"nx\">records<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">json<\/span><span class=\"p\">.<\/span><span class=\"nx\">Records<\/span><span class=\"p\">;<\/span>\r\n    <span class=\"kd\">var<\/span> <span class=\"nx\">searchRecords<\/span> <span class=\"o\">=<\/span> <span class=\"p\">[];<\/span>\r\n    <span class=\"k\">for<\/span><span class=\"p\">(<\/span><span class=\"kd\">var<\/span> <span class=\"nx\">i<\/span> <span class=\"o\">=<\/span> <span class=\"mi\">0<\/span><span class=\"p\">;<\/span> <span class=\"nx\">i<\/span> <span class=\"o\">&lt;<\/span> <span class=\"nx\">records<\/span><span class=\"p\">.<\/span><span class=\"nx\">length<\/span><span class=\"p\">;<\/span> <span class=\"nx\">i<\/span><span class=\"o\">++<\/span><span class=\"p\">){<\/span>\r\n        <span class=\"kd\">var<\/span> <span class=\"nx\">record<\/span> <span class=\"o\">=<\/span> <span class=\"nx\">records<\/span><span class=\"p\">[<\/span><span class=\"nx\">i<\/span><span class=\"p\">];<\/span>\r\n        <span class=\"kd\">var<\/span> <span class=\"nx\">header<\/span> <span class=\"o\">=<\/span> <span class=\"p\">{<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">index<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:{<\/span>\r\n                <span class=\"dl\">\"<\/span><span class=\"s2\">_index<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"nx\">ES_INDEX<\/span><span class=\"p\">,<\/span>\r\n                <span class=\"dl\">\"<\/span><span class=\"s2\">_type<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"nx\">ES_TYPE<\/span><span class=\"p\">,<\/span>\r\n                <span class=\"dl\">\"<\/span><span class=\"s2\">_id<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">eventTime<\/span> <span class=\"o\">+<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">-<\/span><span class=\"dl\">\"<\/span> <span class=\"o\">+<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">requestID<\/span>\r\n            <span class=\"p\">}<\/span>\r\n        <span class=\"p\">};<\/span>\r\n\r\n        <span class=\"kd\">var<\/span> <span class=\"nx\">searchRecord<\/span> <span class=\"o\">=<\/span> <span class=\"p\">{<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">usertype<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">userIdentity<\/span><span class=\"p\">.<\/span><span class=\"nx\">type<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">arn<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">userIdentity<\/span><span class=\"p\">.<\/span><span class=\"nx\">arn<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">accesskeyid<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">userIdentity<\/span><span class=\"p\">.<\/span><span class=\"nx\">accessKeyId<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">username<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">userIdentity<\/span><span class=\"p\">.<\/span><span class=\"nx\">userName<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">eventtime<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">eventTime<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">eventsource<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">eventSource<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">eventname<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">eventName<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">awsregion<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">awsRegion<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">sourceipaddress<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">sourceIPAddress<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">useragent<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">userAgent<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">requestid<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">requestID<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">eventid<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">record<\/span><span class=\"p\">.<\/span><span class=\"nx\">eventID<\/span><span class=\"p\">,<\/span>\r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">logfilename<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"nx\">logFileName<\/span>\r\n        <span class=\"p\">};<\/span>\r\n        <span class=\"nx\">searchRecords<\/span><span class=\"p\">.<\/span><span class=\"nx\">push<\/span><span class=\"p\">(<\/span><span class=\"nx\">header<\/span><span class=\"p\">);<\/span>\r\n        <span class=\"nx\">searchRecords<\/span><span class=\"p\">.<\/span><span class=\"nx\">push<\/span><span class=\"p\">(<\/span><span class=\"nx\">searchRecord<\/span><span class=\"p\">);<\/span>\r\n    <span class=\"p\">};<\/span>\r\n    <span class=\"nx\">console<\/span><span class=\"p\">.<\/span><span class=\"nx\">log<\/span><span class=\"p\">(<\/span><span class=\"nx\">searchRecords<\/span><span class=\"p\">);<\/span>\r\n    <span class=\"nx\">ES_CLIENT<\/span><span class=\"p\">.<\/span><span class=\"nx\">bulk<\/span><span class=\"p\">({<\/span>\r\n        <span class=\"dl\">\"<\/span><span class=\"s2\">body<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"nx\">searchRecords<\/span>\r\n    <span class=\"p\">},<\/span> <span class=\"kd\">function<\/span><span class=\"p\">(<\/span><span class=\"nx\">err<\/span><span class=\"p\">,<\/span> <span class=\"nx\">resp<\/span><span class=\"p\">){<\/span>\r\n            <span class=\"k\">if<\/span><span class=\"p\">(<\/span><span class=\"nx\">err<\/span><span class=\"p\">){<\/span>\r\n                <span class=\"nx\">console<\/span><span class=\"p\">.<\/span><span class=\"nx\">log<\/span><span class=\"p\">(<\/span><span class=\"nx\">err<\/span><span class=\"p\">);<\/span>\r\n                <span class=\"nx\">context<\/span><span class=\"p\">.<\/span><span class=\"nx\">done<\/span><span class=\"p\">(<\/span><span class=\"dl\">\"<\/span><span class=\"s2\">error<\/span><span class=\"dl\">\"<\/span><span class=\"p\">,<\/span><span class=\"nx\">err<\/span><span class=\"p\">);<\/span>\r\n            <span class=\"p\">}<\/span><span class=\"k\">else<\/span><span class=\"p\">{<\/span>\r\n                <span class=\"nx\">console<\/span><span class=\"p\">.<\/span><span class=\"nx\">log<\/span><span class=\"p\">(<\/span><span class=\"nx\">resp<\/span><span class=\"p\">);<\/span>\r\n                <span class=\"nx\">context<\/span><span class=\"p\">.<\/span><span class=\"nx\">done<\/span><span class=\"p\">(<\/span><span class=\"kc\">null<\/span><span class=\"p\">,<\/span><span class=\"dl\">'<\/span><span class=\"s1\">success<\/span><span class=\"dl\">'<\/span><span class=\"p\">);<\/span>\r\n            <span class=\"p\">};<\/span>\r\n    <span class=\"p\">});<\/span>\r\n<span class=\"p\">};<\/span>\r\n<\/code><\/pre>\n<h2>\u7528\u6cd5<\/h2>\n<p>\u8bf7\u63d0\u524d\u542f\u7528CloudTrail\u3002CloudTrail\u65e5\u5fd7\u5e94\u653e\u7f6e\u5728\u4e0eLambda\u51fd\u6570\u76f8\u540c\u7684\u533a\u57df\u5185\u3002<\/p>\n<p>\u9996\u5148\uff0c\u51c6\u5907\u4e00\u53f0\u5b89\u88c5\u4e86Elasticsearch \/ kibana\u7684\u670d\u52a1\u5668\u3002\u7531\u4e8ekibana4\u6700\u8fd1\u5b98\u65b9\u53d1\u5e03\uff0c\u6240\u4ee5\u8fd9\u6b21\u9009\u62e9Elasticsearch 1.4.4\/kibana 4.0\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">http:\/\/www.elasticsearch.org\/download\/<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">http:\/\/www.elasticsearch.org\/overview\/kibana\/installation\/<\/ul>\n<p>\u4e00\u65e6\u542f\u52a8Elasticsearch\uff0c\u5c31\u53ef\u4ee5\u521b\u5efa\u7d22\u5f15\u3002\u5f53\u5411Elasticsearch\u653e\u7f6e\u6587\u6863\u65f6\uff0c\u5b83\u4f1a\u81ea\u52a8\u521b\u5efa\u6620\u5c04\uff0c\u4f46\u5982\u679c\u5728Kibana\u4e2d\u4f7f\u7528\u65f6\uff0c\u6700\u597d\u660e\u786e\u6307\u5b9a\u4e3anot_analyzed\u3002<\/p>\n<pre class=\"post-pre\"><code>curl -XPUT http:\/\/localhost:9200\/cloudtrail -d '\r\n{\r\n    mappings: {\r\n        log: {\r\n            properties: {\r\n                accesskeyid: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                arn: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                awsregion: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                eventid: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                eventname: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                eventsource: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                eventtime: {\r\n                    type: \"date\",\r\n                    format: \"dateOptionalTime\"\r\n                },\r\n                logfilename: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                requestid: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                sourceipaddress: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                useragent: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                username: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                },\r\n                usertype: {\r\n                    type: \"string\",\r\n                    index: \"not_analyzed\"\r\n                }\r\n            }\r\n        }\r\n    }\r\n}'\r\n<\/code><\/pre>\n<p>\u4e00\u65e6Elasticsearch\u73af\u5883\u51c6\u5907\u5c31\u7eea\uff0c\u6211\u4eec\u5c06\u521b\u5efa\u4e00\u4e2alambda function\u3002<\/p>\n<p>\u5b89\u88c5Node\u548cnpm\uff0c\u5e76\u8bbe\u7f6elambda\u51fd\u6570\u7684\u73af\u5883\u4ee5\u6253\u5305\u3002\u8fd9\u91cc\u53c2\u8003\u8bbe\u7f6eLambda\u5f00\u53d1\u73af\u5883\u3002<br \/>\n\u7531\u4e8e\u51fd\u6570\u4e2d\u4f7f\u7528\u4e86Elasticsearch.js\uff0c\u6240\u4ee5\u4f7f\u7528npm\u8fdb\u884c\u5b89\u88c5\u3002<\/p>\n<pre class=\"post-pre\"><code>npm install elasticsearch\r\n<\/code><\/pre>\n<p>\u5c06\u5f00\u5934\u7684Lambda\u51fd\u6570\u4fdd\u5b58\u4e3ajs\u683c\u5f0f\uff0c\u5e76\u4e0enode_module\u4e00\u8d77\u538b\u7f29\u4e3azip\u6587\u4ef6\u3002\u5f53 zip\u6587\u4ef6\u51c6\u5907\u597d\u540e\uff0c\u4e0a\u4f20\u5230Lambda\u4e2d\u3002<br \/>\n\u4f7f\u7528aws cli\u5de5\u5177\uff0c\u4e0a\u4f20\u540e\u4f1a\u76f4\u63a5\u521b\u5efaLambda\u51fd\u6570\u3002<\/p>\n<pre class=\"post-pre\"><code>$ zip -r function.zip lambda-function.js node_modules\r\n\r\n$ aws lambda upload-function --function-name CloudtrailToElasticsearch --function-zip \".\/function.zip\" --runtime nodejs --role  arn:aws:iam::&lt;AWS_ACCOUNT_ID&gt;:role\/lambda_exec_role --mode event --handler lambda-function.handler \r\n<\/code><\/pre>\n<p>\u521b\u5efaLambda\u51fd\u6570\u540e\uff0c\u9700\u8981\u8fdb\u884c\u4e8b\u4ef6\u6e90\u7684\u914d\u7f6e\u3002\u5728Lambda\u7ba1\u7406\u63a7\u5236\u53f0\u4e2d\uff0c\u70b9\u51fb\u201c\u914d\u7f6e\u4e8b\u4ef6\u6e90\u201d\uff0c\u9009\u62e9\u4f5c\u4e3aCloudtrail\u65e5\u5fd7\u8f93\u51fa\u7684S3\u5b58\u50a8\u6876\u4ee5\u53ca\u5728\u8bfb\u53d6\u65f6\u4f7f\u7528\u7684IAM\u89d2\u8272\uff0c\u5e76\u8fdb\u884c\u8bbe\u7f6e\u3002<\/p>\n<p>\u5982\u679c\u60a8\u6309\u7167\u9019\u500b\u8a2d\u5b9a\uff0c\u4e26\u4e14\u6c92\u6709\u4efb\u4f55\u554f\u984c\u7684\u8a71\uff0cCloudTrail\u65e5\u8a8c\u5c07\u81ea\u52d5\u88ab\u63a8\u9001\u5230Elasticsearch\u3002<\/p>\n<p>\u53ea\u9700\u4f7f\u7528Kibana4\u521b\u5efa\u4eea\u8868\u677f\u5373\u53ef\u3002 Kibana4\u7684\u64cd\u4f5c\u975e\u5e38\u6709\u7528\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442237434c4406c9e49f\/19-0.png\" alt=\"SnapCrab_NoName_2015-2-22_12-41-29_No-00.png\" \/><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442237434c4406c9e49f\/20-0.png\" alt=\"SnapCrab_NoName_2015-2-22_12-37-35_No-00.png\" \/><\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u6211\u89c9\u5f97\u628aCloudtrail\u65e5\u5fd7\u653e\u5165\u53ef\u4ee5\u4f7f\u7528Kibana\u7684Elasticsearch\u4e2d\u8fdb\u884c\u5206\u6790\u4f1a\u5f88\u65b9\u4fbf\uff0c [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-41023","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528lambda\u5c06cloudtrail\u65e5\u5fd7\u6295\u653e\u5230elasticsearch\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u6211\u89c9\u5f97\u628aCloudtrail\u65e5\u5fd7\u653e\u5165\u53ef\u4ee5\u4f7f\u7528Kibana\u7684Elasticsearch\u4e2d\u8fdb\u884c\u5206\u6790\u4f1a\u5f88\u65b9\u4fbf\uff0c [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528lambda\u5c06cloudtrail\u65e5\u5fd7\u6295\u653e\u5230elasticsearch\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-27T06:41:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T14:02:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442237434c4406c9e49f\/2-0.png\" \/>\n<meta name=\"author\" content=\"\u6e05, \u626c\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6e05, \u626c\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/\",\"name\":\"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2022-12-27T06:41:41+00:00\",\"dateModified\":\"2024-04-30T14:02:47+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461\",\"name\":\"\u6e05, \u626c\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g\",\"caption\":\"\u6e05, \u626c\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyang\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528lambda\u5c06cloudtrail\u65e5\u5fd7\u6295\u653e\u5230elasticsearch\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch","og_description":"\u9996\u5148 \u6211\u89c9\u5f97\u628aCloudtrail\u65e5\u5fd7\u653e\u5165\u53ef\u4ee5\u4f7f\u7528Kibana\u7684Elasticsearch\u4e2d\u8fdb\u884c\u5206\u6790\u4f1a\u5f88\u65b9\u4fbf\uff0c [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528lambda\u5c06cloudtrail\u65e5\u5fd7\u6295\u653e\u5230elasticsearch\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2022-12-27T06:41:41+00:00","article_modified_time":"2024-04-30T14:02:47+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442237434c4406c9e49f\/2-0.png"}],"author":"\u6e05, \u626c","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6e05, \u626c","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"2 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/","name":"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2022-12-27T06:41:41+00:00","dateModified":"2024-04-30T14:02:47+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528Lambda\u5c06CloudTrail\u65e5\u5fd7\u6295\u653e\u5230Elasticsearch"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461","name":"\u6e05, \u626c","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g","caption":"\u6e05, \u626c"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyang\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8lambda%e5%b0%86cloudtrail%e6%97%a5%e5%bf%97%e6%8a%95%e6%94%be%e5%88%b0elasticsearch%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=41023"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41023\/revisions"}],"predecessor-version":[{"id":94560,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41023\/revisions\/94560"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=41023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=41023"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=41023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}