Sign inSign up

sgaunet/awslogcheck

By sgaunet

•Updated about 1 year ago

Image
0

3.6K

sgaunet/awslogcheck repository overview

⁠awslogcheck

The purpose is to create a tool to parse cloudwatch logs and get a mail report with all occurences that doesn't match with regexp given (like logcheck but for AWS EKS application, considering that logs are stored in cloudwatch thanks to fluentd).

Actually, the program can connect to AWS API through SSO profile or get the default config (need to give permissions to the EC2 that will run the program).

awslogcheck will be spawned every hour and if there are logs that do not fit with rules, you will get an email (Need a mailgun account).

⁠Configuration

The configuration files has the below format :

rulesdir: "/opt/awslogcheck/rules-perso"
imagesToIgnore:
  - fluent/fluentd-kubernetes-daemonset
  - 602401143452.dkr.ecr.eu-west-3.amazonaws.com/eks/kube-proxy
  - docker:stable
  - docker:dind
containerNameToIgnore:
  - aws-vpc-cni-init
  - helper
  - build
  - svc-0

imagesToIgnore and containerNameToIgnore are golang regexp expression, you can test with https://regex101.com/⁠

Some environment variables need to be declared :

MAILGUN_APIKEY: "..."
MAILGUN_DOMAIN: "..."
MAILGROM:
MAILTO: 
SUBJECT: "awslogcheck"
AWS_REGION: eu-west-3
LOGGROUP: "/aws/containerinsights/dev-EKS/application"

Every environment vars are mandatory. The loggroup should be the loggroup created by fluentd deployment. awslogcheck won't be able to check another structure of events.

loggroup

How to write regexp ? You can use https://regex101.com/⁠ to check your regexp (golang regexp).

Source code is here⁠

Tag summary

Content type

Image

Digest

sha256:3ca4d6fed…

Size

6.8 MB

Last updated

about 1 year ago

docker pull sgaunet/awslogcheck