Kanji
・云架构工程师 / 自由职业 ・1993年出生 ・爱媛县出身 / 现居东京都涩谷区 ・5年 AWS 实战经验 个人资料详情
目录
cfn-guard validate \ --rules ~/cis-aws-benchmark-level-1.guard \ --data ./template.yml
s3:PutObject
s3:GetBucketLocation
AWSTemplateFormatVersion: 2010-09-09 Resources: AthenaBucket01: Type: AWS::S3::Bucket Properties: BucketName: !Sub sample-athena-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: SSEAlgorithm: AES256 LifecycleConfiguration: Rules: - Status: Enabled ExpirationInDays: 45 Prefix: athena-query-resultsd/ - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true LoggingConfiguration: DestinationBucketName: !Sub sample-server-access-log-bucket-${AWS::AccountId}-${AWS::Region} TargetObjectKeyFormat: PartitionedPrefix: PartitionDateSource: EventTime VersioningConfiguration: Status: Enabled AthenaBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref AthenaBucket01 PolicyDocument: Version: 2012-10-17 Statement: - Sid: AllowAthenaGetBucketLocation Effect: Allow Principal: Service: - !Sub athena.${AWS::Region}.amazonaws.com Action: - s3:GetBucketLocation - s3:PutObject Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* # 参考: https://docs.aws.amazon.com/ja_jp/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* Condition: Bool: aws:SecureTransport: false AthenaWorkgroup01: Type: AWS::Athena::WorkGroup Properties: Name: sample-athena-workgroup State: ENABLED WorkGroupConfiguration: EngineVersion: SelectedEngineVersion: AUTO ResultConfiguration: OutputLocation: !Sub s3://${AthenaBucket01}/athena-query-results/ EncryptionConfiguration: EncryptionOption: SSE_S3
以下 CloudFormation 模板配置 Glue 数据库,用于分析 【IaC】Amazon S3 示例代码集合 中描述的审核日志存储桶和服务器访问日志存储桶中累积的日志。
支持的 AWS 服务包括 AWS Config、AWS CloudTrail、Amazon GuardDuty、Amazon VPC 流日志和 S3 服务器访问日志。
创建一个包含五个表的数据库:
CloudTrail 表
配置表
警卫值班表
VPC流日志表
服务器访问日志表
对于所有表,使用分区投影设置三个分区键:“account”、“region”和“timestamp”。
account 是一个 12 位整数, region 是 AWS 区域名称的字符串类型,而 timestamp 是日期类型,范围从七年前到现在。
account
region
timestamp
此外,“region”是列出 AWS 区域名称的枚举类型。
对于服务器访问日志表,添加了一个额外的分区键“source_bucket_name”。
设置为记录服务器访问日志的 S3 存储桶名称的分区键。
````yaml AWSTemplateFormat版本:2010-09-09 资源: 胶水数据库01: 类型:AWS::Glue::数据库 特性: 数据库输入: 名称:sample_glue_database CatalogId: !Ref AWS::AccountId
云踪表01: 类型:AWS::Glue::Table 特性: 数据库名称:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表输入: 表类型:EXTERNAL_TABLE 名称:cloud_trail 分区键: - 名称:账户 类型:字符串 - 名称:地区 类型:字符串 - 名称:时间戳 类型:字符串 参数: 投影.启用:true 投影.帐户.类型:整数 投影.帐户.数字: 12 投影.帐户.范围: 000000000000,999999999999 projection.timestamp.type:日期 投影.时间戳.范围:现在-7年,现在 投影.时间戳.格式:yyyy/MM/dd 投影.时间戳.间隔: 1 投影.时间戳.间隔.单位:天 投影.区域.类型:枚举 投影.区域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 外部:正确 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C l o u d T r a i l / {!region}/ ! t i m e s t a m p 存 储 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 输入格式:com.amazon.emr.cloudtrail.CloudTrailInputFormat 输出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 压缩:假 串行信息: 序列化库:com.amazon.emr.hive.serde.CloudTrailSerde 存储为子目录: false 栏目: - 名称:事件版本 类型:字符串 - 名称:用户身份 类型: struct<type:string,principalId:string,arn:string,accountId:string,invokedBy:string,accessKeyId:string,userName:string,sessionContext:struct<attributes:struct<mfaAuthenticated:string,creationDate:string>,sessionIssuer:struct<type:string,principalId:string,arn:string,accountId:string,userName:string>>> - 名称:活动时间 类型:字符串 - 名称:事件源 类型:字符串 - 名称:活动名称 类型:字符串 - 名称:awsregion 类型:字符串 - 名称:源 IP 地址 类型:字符串 - 名称:用户代理 类型:字符串 - 名称:错误代码 类型:字符串 - 名称:错误消息 类型:字符串 - 名称:请求参数 类型:字符串 - 名称:响应元素 类型:字符串 - 名称:附加事件数据 类型:字符串 - 名称:请求ID 类型:字符串 - 名称:事件ID 类型:字符串 - 名称:资源 类型:数组<struct<arn:string,accountId:string,type:string>> - 名称:事件类型 类型:字符串 - 名称:apiversion 类型:字符串 - 名称:只读 类型:字符串 - 名称:收件人帐户 ID 类型:字符串 - 名称:服务事件详细信息 类型:字符串 - 名称:sharedeventid 类型:字符串 - 名称:vpcendpointid 类型:字符串
配置表01: 类型:AWS::Glue::Table 特性: CatalogId: !Ref AWS::AccountId 数据库名称:!Ref GlueDatabase01 表输入: 名称:配置 分区键: - 名称:账户 类型:字符串 - 名称:地区 类型:字符串 - 名称:时间戳 类型:字符串 参数: 投影.启用:true 投影.帐户.类型:整数 投影.帐户.数字: 12 投影.帐户.范围: 000000000000,999999999999 projection.timestamp.type:日期 投影.时间戳.范围:现在-7年,现在 投影.时间戳.格式:yyyy/MM/dd 投影.时间戳.间隔: 1 投影.时间戳.间隔.单位:天 投影.区域.类型:枚举 投影.区域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C o n f i g / {!region}/ ! t i m e s t a m p 表 类 型 : E X T E R N A L T A B L E 存 储 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 输入格式:com.amazon.emr.cloudtrail.CloudTrailInputFormat 输出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 串行信息: 序列化库:org.apache.hive.hcatalog.data.JsonSerDe 栏目: - 名称:文件版本 类型:字符串 - 名称:configSnapshotId 类型:字符串 - 名称:配置项 类型:数组<结构<configurationItemVersion:字符串,configurationItemCaptureTime:字符串,configurationStateId:bigint,awsAccountId:字符串,configurationItemStatus:字符串,resourceType:字符串,resourceId:字符串,resourceName:字符串,ARN:字符串,awsRegion:字符串,availabilityZone:字符串,configurationStateMd5Hash:字符串,resourceCreationTime:字符串>>
警卫值班表01: 类型:AWS::Glue::Table 特性: 数据库名称:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表输入: 表类型:EXTERNAL_TABLE 名称:守卫值班 分区键: - 名称:账户 类型:字符串 - 名称:地区 类型:字符串 - 名称:时间戳 类型:字符串 参数: 投影.启用:true 投影.帐户.类型:整数 投影.帐户.数字: 12 投影.帐户.范围: 000000000000,999999999999 projection.timestamp.type:日期 投影.时间戳.范围:NOW-1年,现在 投影.时间戳.格式:yyyy/MM/dd 投影.时间戳.间隔: 1 投影.时间戳.间隔.单位:天 投影.区域.类型:枚举 投影.区域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 外部:正确 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / G u a r d D u t y / {!region}/ ! t i m e s t a m p 存 储 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 输入格式:org.apache.hadoop.mapred.TextInputFormat 输出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 压缩:假 串行信息: 序列化库:org.openx.data.jsonserde.JsonSerDe 存储为子目录: false 栏目: - 名称:架构版本 类型:字符串 - 名称:账户ID 类型:字符串 - 名称:地区 类型:字符串 - 名称:分区 类型:字符串 - 姓名:身份证号 类型:字符串 - 姓名:阿恩 类型:字符串 - 名称:类型 类型:字符串 - 名称:资源 类型: struct<resourcetype:string,accesskeydetails:struct<accesskeyid:string,principalid:string,usertype:string,username:string>> - 名称:服务 类型:struct<servicename:string,Detectorid:string,action:struct<actiontype:string,awsapicallaction:struct<api:string,servicename:string,callertype:string,remoteipdetails:struct<ipaddressv4:string,organization:struct<asn:string,asnorg:string,isp:string,org:string>,country:struct<国家/地区名称:字符串>,城市:结构<城市名称:字符串>,地理位置:结构<纬度:浮点,经度:浮点>>,受影响的资源:字符串>>,资源角色:字符串,附加信息:结构<recentapicalls:数组<结构<api:字符串,计数:int>>>,证据:字符串,eventfirstseen:字符串,eventlastseen:字符串,存档:布尔值,计数:int> - 名称:严重性 类型:整数 - 名称:创建于 类型:字符串 - 名称:更新日期 类型:字符串 - 姓名:标题 类型:字符串 - 名称:描述 类型:字符串
VPCFlowLogs表01: 类型:AWS::Glue::Table 特性: 数据库名称:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表输入: 表类型:EXTERNAL_TABLE 名称:vpc_flow_logs 分区键: - 名称:账户 类型:字符串 - 名称:地区 类型:字符串 - 名称:时间戳 类型:字符串 参数: 投影.启用:true 投影.帐户.类型:整数 投影.帐户.数字: 12 投影.帐户.范围: 000000000000,999999999999 projection.timestamp.type:日期 投影.时间戳.范围:现在-7年,现在 投影.时间戳.格式:yyyy/MM/dd 投影.时间戳.间隔: 1 投影.时间戳.间隔.单位:天 投影.区域.类型:枚举 投影.区域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 外部:正确 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / v p c f l o w l o g s / {!region}/ ! t i m e s t a m p 存 储 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 输入格式:org.apache.hadoop.mapred.TextInputFormat 输出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 串行信息: 序列化库:org.apache.hadoop.hive.serde2.lazy.LazySimpleSerDe 参数: 字段.delim: ’ ’ 跳过标题行数:1 参数: 分类: 文本文件 跳过标题行数:1 栏目: - 名称:版本 类型:整数 - 名称:account_id 类型:字符串 - 名称:interface_id 类型:字符串 - 名称:srcaddr 类型:字符串 - 名称:dstaddr 类型:字符串 - 名称:srcport 类型:整数 - 名称:目的地端口 类型:整数 - 名称:协议 类型:bigint - 名称:数据包 类型:bigint - 名称:字节 类型:bigint - 名称:开始 类型:bigint - 名称:结束 类型:bigint - 名称:行动 类型:字符串 - 名称:vpc_id 类型:字符串 - 名称:subnet_id 类型:字符串 - 名称:instance_id 类型:字符串 - 名称:tcp_flags 类型:整数 - 名称:类型 类型:字符串 - 名称:pkt_srcaddr 类型:字符串 - 名称:pkt_dstaddr 类型:字符串 - 名称:az_id 类型:字符串 - 名称:子位置_类型 类型:字符串 - 名称:sublocation_id 类型:字符串 - 名称:pkt_src_aws_service 类型:字符串 - 名称:pkt_dst_aws_service 类型:字符串 - 名称:流向 类型:字符串 - 名称:交通路径 类型:整数
服务器访问日志表01: 类型:AWS::Glue::Table 特性: 数据库名称:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表输入: 名称:服务器访问日志 表类型:EXTERNAL_TABLE 分区键: - 名称:账户 类型:字符串 - 名称:地区 类型:字符串 - 名称:时间戳 类型:字符串 - 名称:源存储桶名称 类型:字符串 参数: 投影.启用:true 投影.帐户.类型:整数 投影.帐户.数字: 12 投影.帐户.范围: 000000000000,999999999999 投影.时间戳.格式:yyyy/MM/dd 投影.时间戳.间隔: 1 投影.时间戳.间隔.单位:天 投影.时间戳.范围:现在-7年,现在 projection.timestamp.type:日期 投影.区域.类型:枚举 投影.区域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 projection.source_bucket_name.type:注入 storage.location.template: !Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ ! a c c o u n t / {!region}/ ! s o u r c e b u c k e t n a m e / {!timestamp} 存储描述符: 位置:!Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ 输入格式:org.apache.hadoop.mapred.TextInputFormat 输出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 串行信息: 序列化库:org.apache.hadoop.hive.serde2.RegexSerDe 参数: input.regex: ’([^ ] ) ([^ ] ) [(. ?)] ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ("[^\"] "|-) (-|[0-9] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] )([^ ] ) ([^ ] ) ("[^\"] "|-) ([^ ] )(?: ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ))?.*$’ 栏目: - 姓名:bucketowner 类型:字符串 - 名称:bucket_name 类型:字符串 - 名称:请求日期时间 类型:字符串 - 名称:remoteip 类型:字符串 - 姓名:请求者 类型:字符串 - 名称:请求ID 类型:字符串 - 名称:操作 类型:字符串 - 名称:钥匙 类型:字符串 - 名称:request_uri 类型:字符串 - 名称:httpstatus 类型:字符串 - 名称:错误代码 类型:字符串 - 名称:字节发送 类型:bigint - 名称:对象大小 类型:bigint - 名称:总时间 类型:字符串 - 名称:周转时间 类型:字符串 - 姓名:推荐人 类型:字符串 - 名称:用户代理 类型:字符串 - 名称:版本号 类型:字符串 - 名称:主机ID 类型:字符串 - 名称:sigv 类型:字符串 - 名称:密码套件 类型:字符串 - 名称:验证类型 类型:字符串 - 名称:端点 类型:字符串 - 名称:tlsversion 类型:字符串 - 名称:接入点arn 类型:字符串 - 名称:acl必填 类型:字符串