Skip to content

Add AWS CloudTrail parser (JSON audit log) - #35

Merged
copyleftdev merged 1 commit into
mainfrom
feat/cloudtrail
May 31, 2026
Merged

copyleftdev merged 1 commit into
mainfrom
feat/cloudtrail

Conversation

@copyleftdev

Copy link
Copy Markdown
Owner

Implements the AWS CloudTrail plugin — issue #11.

What

A CloudTrail file is a single JSON document with a top-level Records array;
each record becomes one row, flattened depth-1:

  • top-level scalars → columns (eventName, eventSource, sourceIPAddress, …);
  • nested objects → parent.child columns (userIdentity.userName,
    userIdentity.type);
  • anything deeper or array-valued (requestParameters, responseElements) →
    canonical JSON string, so a varied per-API payload doesn't explode the schema.

It also synthesizes eventEpoch — the RFC 3339 eventTime parsed to Unix
seconds via chrono (deterministic; no wall clock) — so --cadence eventEpoch
and the contextual detector (--period 24) can read the call series for
off-hours / automated-pattern anomalies, while eventName feeds rare-API dist
drift.

Routing

  • Detected by a Records array whose entries carry eventName (STRONG),
    registered ahead of NDJSON/JSON.
  • Claims no extension — CloudTrail is delivered as *.json (owned by the
    JSON parser); pipe it on stdin for CloudTrail-aware flattening.

Errors

Missing Records, a non-object record, and non-JSON are clean AxError::Parse.

Gates

  • fmt / clippy -D warnings / full workspace tests green (both feature sets).
  • Mutation gate: 0 surviving mutants on cloudtrail.rs. The extensions()
    → empty-slice mutant is a documented equivalent (same as Zeek/Journal/Eve).
  • Smoke: a Records document routes as cloudtrail; an automated call burst is
    flagged by --cadence eventEpoch (exit 1).

Closes #11

🤖 Generated with Claude Code

New CloudTrailParser in ax-normalize. A CloudTrail file is a single JSON
document with a top-level Records array; each record becomes one row, flattened
depth-1: top-level scalars are columns (eventName, eventSource, sourceIPAddress,
...), nested objects contribute parent.child columns (userIdentity.userName,
userIdentity.type), and anything deeper or array-valued (requestParameters,
responseElements) is kept as canonical JSON so a varied per-API payload does not
explode the schema.

Synthesizes eventEpoch — the RFC 3339 eventTime parsed to Unix seconds via
chrono (deterministic; no wall clock) — so --cadence eventEpoch and the
contextual detector (--period 24) can read the call series for off-hours /
automated-pattern anomalies, while eventName feeds rare-API dist drift.

Detected by a Records array whose entries carry eventName (STRONG); claims no
extension (CloudTrail is delivered as *.json, owned by the JSON parser). Missing
Records, a non-object record, and non-JSON are clean Parse errors.

Mutation gate: 0 surviving mutants on the new file. The extensions() ->
empty-slice mutant is a documented equivalent (same as Zeek/Journal/Eve).

Closes #11

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 31, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@copyleftdev, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 10 minutes and 22 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 672f74b3-4a5b-488a-84d1-31b17e7c1e8c

📥 Commits

Reviewing files that changed from the base of the PR and between 56747bb and 4fdc2d0.

📒 Files selected for processing (4)
  • .cargo/mutants.toml
  • crates/ax-normalize/src/parser.rs
  • crates/ax-normalize/src/parsers/cloudtrail.rs
  • crates/ax-normalize/src/parsers/mod.rs
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/cloudtrail

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@copyleftdev
copyleftdev merged commit db69ad5 into main May 31, 2026
2 checks passed
@copyleftdev
copyleftdev deleted the feat/cloudtrail branch May 31, 2026 06:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add an AWS CloudTrail parser (JSON audit log)

1 participant