ingest-cloudtrail-ocsf
ingest-cloudtrail-ocsf
Thin, single-purpose ingestion skill: raw CloudTrail JSON in → canonical event projection → OCSF 1.8 API Activity JSONL or native enriched JSONL out. No detection logic, no side effects, no AWS API calls. Reads files or stdin; writes JSONL or stdout.
Wire contract
Reads either of the two CloudTrail layouts that are emitted by the AWS service:
- Single event — one JSON object per line (NDJSON, e.g. EventBridge → Kinesis Firehose to S3)
- CloudTrail digest — top-level
{"Records": [...]}wrapping an array of events (the formataws s3 cpretrieves directly from the CloudTrail bucket)
The skill auto-detects which shape it's looking at and unwraps Records if present.
By default it writes OCSF 1.8 API Activity (class_uid: 6003, category_uid: 6). See ../OCSF_CONTRACT.md for the field-level pinning that every OCSF event matches.
When --output-format native is selected, it emits the same event in the repo's native enriched shape with stable event_uid, normalized provider/account/operation/status fields, and preserved actor/session/source context, but without the OCSF envelope fields.