aws-msk-broker-log-destination

Broker logs can expose client principal names, topic names, connection errors, and occasionally authentication/configuration details.

awshigh service: aws:msk emits ContainsSecret

Where it sits

locationCloudWatch Logs/S3/Firehose MSK broker log record
location kindlog_field
data kindscredential password sensitive_data pii
emits edgeContainsSecret
serviceMSK (Kafka) (aws:msk)

Collection recipe

access modeindirect_destination
operationlogs:FilterLogEvents or s3:GetObject
response pathlog event or object body
encodingstring
params{"Destination": "\u003cbroker-log-destination\u003e"}

Required permissions

kafka:DescribeClusterV2
logs:FilterLogEvents

References

move · open · esc close