Class ParseToOCSF
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<ParseToOCSF.Builder,ParseToOCSF>
This processor converts logs into Open Cybersecurity Schema Framework (OCSF) events.
For more information about this processor including examples, see parseToOSCF in the CloudWatch Logs User Guide.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionstatic ParseToOCSF.Builderbuilder()final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final EventSourceSpecify the service or process that produces the log events that will be converted with this processor.final StringSpecify the service or process that produces the log events that will be converted with this processor.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final inthashCode()final OCSFVersionSpecify which version of the OCSF schema to use for the transformed log events.final StringSpecify which version of the OCSF schema to use for the transformed log events.static Class<? extends ParseToOCSF.Builder> final Stringsource()The path to the field in the log event that you want to parse.Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
source
The path to the field in the log event that you want to parse. If you omit this value, the whole log message is parsed.
- Returns:
- The path to the field in the log event that you want to parse. If you omit this value, the whole log message is parsed.
-
eventSource
Specify the service or process that produces the log events that will be converted with this processor.
If the service returns an enum value that is not available in the current SDK version,
eventSourcewill returnEventSource.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromeventSourceAsString().- Returns:
- Specify the service or process that produces the log events that will be converted with this processor.
- See Also:
-
eventSourceAsString
Specify the service or process that produces the log events that will be converted with this processor.
If the service returns an enum value that is not available in the current SDK version,
eventSourcewill returnEventSource.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromeventSourceAsString().- Returns:
- Specify the service or process that produces the log events that will be converted with this processor.
- See Also:
-
ocsfVersion
Specify which version of the OCSF schema to use for the transformed log events.
If the service returns an enum value that is not available in the current SDK version,
ocsfVersionwill returnOCSFVersion.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromocsfVersionAsString().- Returns:
- Specify which version of the OCSF schema to use for the transformed log events.
- See Also:
-
ocsfVersionAsString
Specify which version of the OCSF schema to use for the transformed log events.
If the service returns an enum value that is not available in the current SDK version,
ocsfVersionwill returnOCSFVersion.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromocsfVersionAsString().- Returns:
- Specify which version of the OCSF schema to use for the transformed log events.
- See Also:
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<ParseToOCSF.Builder,ParseToOCSF> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-
sdkFieldNameToField
- Specified by:
sdkFieldNameToFieldin interfaceSdkPojo- Returns:
- The mapping between the field name and its corresponding field.
-