The purpose is to create a tool to parse cloudwatch logs and get a mail report with all occurences that doesn't match with regexp given (like logcheck but for AWS EKS application, considering that logs are stored in cloudwatch thanks to fluentd).
Actually, the program can connect to AWS API through SSO profile or get the default config (need to give permissions to the EC2 that will run the program).
awslogcheck will be spawned every hour and if there are logs that do not fit with rules, you will get an email (Need a mailgun account).
The configuration files has the below format :
rulesdir: "/opt/awslogcheck/rules-perso"
imagesToIgnore:
- fluent/fluentd-kubernetes-daemonset
- 602401143452.dkr.ecr.eu-west-3.amazonaws.com/eks/kube-proxy
- docker:stable
- docker:dind
containerNameToIgnore:
- aws-vpc-cni-init
- helper
- build
- svc-0
imagesToIgnore and containerNameToIgnore are golang regexp expression, you can test with https://regex101.com/
Some environment variables need to be declared :
MAILGUN_APIKEY: "..."
MAILGUN_DOMAIN: "..."
MAILGROM:
MAILTO:
SUBJECT: "awslogcheck"
AWS_REGION: eu-west-3
LOGGROUP: "/aws/containerinsights/dev-EKS/application"
Every environment vars are mandatory. The loggroup should be the loggroup created by fluentd deployment. awslogcheck won't be able to check another structure of events.

How to write regexp ? You can use https://regex101.com/ to check your regexp (golang regexp).
Content type
Image
Digest
sha256:3ca4d6fed…
Size
6.8 MB
Last updated
about 1 year ago
docker pull sgaunet/awslogcheck