Repository navigation
Add AWS CloudTrail parser (JSON audit log) - #35
Conversation
New CloudTrailParser in ax-normalize. A CloudTrail file is a single JSON document with a top-level Records array; each record becomes one row, flattened depth-1: top-level scalars are columns (eventName, eventSource, sourceIPAddress, ...), nested objects contribute parent.child columns (userIdentity.userName, userIdentity.type), and anything deeper or array-valued (requestParameters, responseElements) is kept as canonical JSON so a varied per-API payload does not explode the schema. Synthesizes eventEpoch — the RFC 3339 eventTime parsed to Unix seconds via chrono (deterministic; no wall clock) — so --cadence eventEpoch and the contextual detector (--period 24) can read the call series for off-hours / automated-pattern anomalies, while eventName feeds rare-API dist drift. Detected by a Records array whose entries carry eventName (STRONG); claims no extension (CloudTrail is delivered as *.json, owned by the JSON parser). Missing Records, a non-object record, and non-JSON are clean Parse errors. Mutation gate: 0 surviving mutants on the new file. The extensions() -> empty-slice mutant is a documented equivalent (same as Zeek/Journal/Eve). Closes #11 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 10 minutes and 22 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Implements the AWS CloudTrail plugin — issue #11.
What
A CloudTrail file is a single JSON document with a top-level
Recordsarray;each record becomes one row, flattened depth-1:
eventName,eventSource,sourceIPAddress, …);parent.childcolumns (userIdentity.userName,userIdentity.type);requestParameters,responseElements) →canonical JSON string, so a varied per-API payload doesn't explode the schema.
It also synthesizes
eventEpoch— the RFC 3339eventTimeparsed to Unixseconds via
chrono(deterministic; no wall clock) — so--cadence eventEpochand the
contextualdetector (--period 24) can read the call series foroff-hours / automated-pattern anomalies, while
eventNamefeeds rare-APIdistdrift.
Routing
Recordsarray whose entries carryeventName(STRONG),registered ahead of NDJSON/JSON.
*.json(owned by theJSON parser); pipe it on stdin for CloudTrail-aware flattening.
Errors
Missing
Records, a non-object record, and non-JSON are cleanAxError::Parse.Gates
fmt/clippy -D warnings/ full workspace tests green (both feature sets).cloudtrail.rs. Theextensions()→ empty-slice mutant is a documented equivalent (same as Zeek/Journal/Eve).
Recordsdocument routes ascloudtrail; an automated call burst isflagged by
--cadence eventEpoch(exit 1).Closes #11
🤖 Generated with Claude Code