Class ParseToOCSF
- All Implemented Interfaces:
Serializable
,SdkPojo
,ToCopyableBuilder<ParseToOCSF.Builder,
ParseToOCSF>
This processor converts logs into Open Cybersecurity Schema Framework (OCSF) events.
For more information about this processor including examples, see parseToOSCF in the CloudWatch Logs User Guide.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionstatic ParseToOCSF.Builder
builder()
final boolean
final boolean
equalsBySdkFields
(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final EventSource
Specify the service or process that produces the log events that will be converted with this processor.final String
Specify the service or process that produces the log events that will be converted with this processor.final <T> Optional
<T> getValueForField
(String fieldName, Class<T> clazz) final int
hashCode()
final OCSFVersion
Specify which version of the OCSF schema to use for the transformed log events.final String
Specify which version of the OCSF schema to use for the transformed log events.static Class
<? extends ParseToOCSF.Builder> final String
source()
The path to the field in the log event that you want to parse.Take this object and create a builder that contains all of the current property values of this object.final String
toString()
Returns a string representation of this object.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
source
The path to the field in the log event that you want to parse. If you omit this value, the whole log message is parsed.
- Returns:
- The path to the field in the log event that you want to parse. If you omit this value, the whole log message is parsed.
-
eventSource
Specify the service or process that produces the log events that will be converted with this processor.
If the service returns an enum value that is not available in the current SDK version,
eventSource
will returnEventSource.UNKNOWN_TO_SDK_VERSION
. The raw value returned by the service is available fromeventSourceAsString()
.- Returns:
- Specify the service or process that produces the log events that will be converted with this processor.
- See Also:
-
eventSourceAsString
Specify the service or process that produces the log events that will be converted with this processor.
If the service returns an enum value that is not available in the current SDK version,
eventSource
will returnEventSource.UNKNOWN_TO_SDK_VERSION
. The raw value returned by the service is available fromeventSourceAsString()
.- Returns:
- Specify the service or process that produces the log events that will be converted with this processor.
- See Also:
-
ocsfVersion
Specify which version of the OCSF schema to use for the transformed log events.
If the service returns an enum value that is not available in the current SDK version,
ocsfVersion
will returnOCSFVersion.UNKNOWN_TO_SDK_VERSION
. The raw value returned by the service is available fromocsfVersionAsString()
.- Returns:
- Specify which version of the OCSF schema to use for the transformed log events.
- See Also:
-
ocsfVersionAsString
Specify which version of the OCSF schema to use for the transformed log events.
If the service returns an enum value that is not available in the current SDK version,
ocsfVersion
will returnOCSFVersion.UNKNOWN_TO_SDK_VERSION
. The raw value returned by the service is available fromocsfVersionAsString()
.- Returns:
- Specify which version of the OCSF schema to use for the transformed log events.
- See Also:
-
toBuilder
Description copied from interface:ToCopyableBuilder
Take this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilder
in interfaceToCopyableBuilder<ParseToOCSF.Builder,
ParseToOCSF> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojo
Indicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojo
class, and is generated based on a service model.If an
SdkPojo
class does not have any inherited fields,equalsBySdkFields
andequals
are essentially the same.- Specified by:
equalsBySdkFields
in interfaceSdkPojo
- Parameters:
obj
- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-
sdkFieldNameToField
- Specified by:
sdkFieldNameToField
in interfaceSdkPojo
- Returns:
- The mapping between the field name and its corresponding field.
-