예제: AWS CloudTrail을 통한 Amazon EventBridge에서 S3 Batch Operations 작업 추적하기

예제: AWS CloudTrail을 통한 Amazon EventBridge에서 S3 Batch Operations 작업 추적하기

S3 Batch Operations 작업의 활동은 AWS CloudTrail에 이벤트로 기록돼요. Amazon EventBridge에 커스텀 규칙을 만들고 Amazon Simple Notification Service(Amazon SNS) 같은 원하는 대상 알림 리소스로 이 이벤트를 보낼 수 있죠. 작업이 거치는 상태 변화를 이벤트로 잡아 알림을 받아 보세요.

출처: 문서

본문

Amazon S3 Batch Operations 작업 활동은 AWS CloudTrail에 이벤트로 기록돼요. Amazon EventBridge에 커스텀 규칙을 만들고, 이 이벤트를 Amazon Simple Notification Service(Amazon SNS) 같은 선택한 대상 알림 리소스로 보낼 수 있어요.

참고 Amazon EventBridge는 이벤트를 관리하는 권장 방법이에요. Amazon CloudWatch Events와 EventBridge는 동일한 기본 서비스와 API를 공유하지만, EventBridge가 더 많은 기능을 제공해요. CloudWatch나 EventBridge 중 어디서 변경해도 각 콘솔에 모두 반영돼요. 자세한 내용은 Amazon EventBridge User Guide 문서를 참고하세요.

  • CloudTrail에 기록되는 S3 Batch Operations 이벤트
  • S3 Batch Operations 작업 이벤트를 추적하는 EventBridge 규칙

CloudTrail에 기록되는 S3 Batch Operations 이벤트

Batch Operations 작업이 만들어지면 CloudTrail에 JobCreated 이벤트로 기록돼요. 작업이 실행되면서 처리 중 상태가 바뀌면 다른 JobStatusChanged 이벤트들이 CloudTrail에 기록돼요. 이 이벤트들은 CloudTrail 콘솔에서 볼 수 있어요. CloudTrail에 대한 자세한 내용은 AWS CloudTrail User Guide 문서를 참고하세요.

참고 S3 Batch Operations 상태 변경 이벤트만 CloudTrail에 기록돼요.

{
    "eventVersion": "1.05",
    "userIdentity": {
        "accountId": "123456789012",
        "invokedBy": "s3.amazonaws.com"
    },
    "eventTime": "2020-02-05T18:25:30Z",
    "eventSource": "s3.amazonaws.com",
    "eventName": "JobStatusChanged",
    "awsRegion": "us-west-2",
    "sourceIPAddress": "s3.amazonaws.com",
    "userAgent": "s3.amazonaws.com",
    "requestParameters": null,
    "responseElements": null,
    "eventID": "f907577b-bf3d-4c53-b9ed-8a83a118a554",
    "readOnly": false,
    "eventType": "AwsServiceEvent",
    "recipientAccountId": "123412341234",
    "serviceEventDetails": {
        "jobId": "d6e58ec4-897a-4b6d-975f-10d7f0fb63ce",
        "jobArn": "arn:aws:s3:us-west-2:181572960644:job/d6e58ec4-897a-4b6d-975f-10d7f0fb63ce",
        "status": "Complete",
        "jobEventId": "b268784cf0a66749f1a05bce259804f5",
        "failureCodes": [],
        "statusChangeReason": []
    }
}

S3 Batch Operations 작업 이벤트를 추적하는 EventBridge 규칙

다음 예제는 AWS CloudTrail이 기록한 S3 Batch Operations 이벤트를 선택한 대상으로 캡처하는 규칙을 Amazon EventBridge에 만드는 방법을 보여줘요.

이렇게 하려면 Creating EventBridge rules that react to events 문서의 모든 단계를 따라 규칙을 만들어요. 해당하는 곳에 다음 S3 Batch Operations 커스텀 이벤트 패턴 정책을 붙여 넣고, 원하는 대상 서비스를 선택하면 돼요.

S3 Batch Operations 커스텀 이벤트 패턴 정책

{
    "source": [
        "aws.s3"
    ],
    "detail-type": [
        "AWS Service Event via CloudTrail"
    ],
    "detail": {
        "eventSource": [
            "s3.amazonaws.com"
        ],
        "eventName": [
            "JobCreated",
            "JobStatusChanged"
        ]
    }
}

다음 예제들은 EventBridge 이벤트 규칙에서 Amazon Simple Queue Service(Amazon SQS)로 보낸 두 개의 Batch Operations 이벤트예요. Batch Operations 작업은 처리되는 동안 많은 다른 상태(New, Preparing, Active 등)를 거치므로, 작업마다 여러 메시지를 받을 수 있을 거예요.

{
    "version": "0",
    "id": "51dc8145-541c-5518-2349-56d7dffdf2d8",
    "detail-type": "AWS Service Event via CloudTrail",
    "source": "aws.s3",
    "account": "123456789012",
    "time": "2020-02-27T15:25:49Z",
    "region": "us-east-1",
    "resources": [],
    "detail": {
        "eventVersion": "1.05",
        "userIdentity": {
            "accountId": "11112223334444",
            "invokedBy": "s3.amazonaws.com"
        },
        "eventTime": "2020-02-27T15:25:49Z",
        "eventSource": "s3.amazonaws.com",
        "eventName": "JobCreated",
        "awsRegion": "us-east-1",
        "sourceIPAddress": "s3.amazonaws.com",
        "userAgent": "s3.amazonaws.com",
        "eventID": "7c38220f-f80b-4239-8b78-2ed867b7d3fa",
        "readOnly": false,
        "eventType": "AwsServiceEvent",
        "serviceEventDetails": {
            "jobId": "e849b567-5232-44be-9a0c-40988f14e80c",
            "jobArn": "arn:aws:s3:us-east-1:181572960644:job/e849b567-5232-44be-9a0c-40988f14e80c",
            "status": "New",
            "jobEventId": "f177ff24f1f097b69768e327038f30ac",
            "failureCodes": [],
            "statusChangeReason": []
        }
    }
}
{
  "version": "0",
  "id": "c8791abf-2af8-c754-0435-fd869ce25233",
  "detail-type": "AWS Service Event via CloudTrail",
  "source": "aws.s3",
  "account": "123456789012",
  "time": "2020-02-27T15:26:42Z",
  "region": "us-east-1",
  "resources": [],
  "detail": {
    "eventVersion": "1.05",
    "userIdentity": {
      "accountId": "1111222233334444",
      "invokedBy": "s3.amazonaws.com"
    },
    "eventTime": "2020-02-27T15:26:42Z",
    "eventSource": "s3.amazonaws.com",
    "eventName": "JobStatusChanged",
    "awsRegion": "us-east-1",
    "sourceIPAddress": "s3.amazonaws.com",
    "userAgent": "s3.amazonaws.com",
    "eventID": "0238c1f7-c2b0-440b-8dbd-1ed5e5833afb",
    "readOnly": false,
    "eventType": "AwsServiceEvent",
    "serviceEventDetails": {
      "jobId": "e849b567-5232-44be-9a0c-40988f14e80c",
      "jobArn": "arn:aws:s3:us-east-1:181572960644:job/e849b567-5232-44be-9a0c-40988f14e80c",
      "status": "Complete",
      "jobEventId": "51f5ac17dba408301d56cd1b2c8d1e9e",
      "failureCodes": [],
      "statusChangeReason": []
    }
  }
}