import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS CloudWatch Observability Admin Telemetry Rule. * * A telemetry rule defines how telemetry data (logs, metrics, or traces) should be collected for AWS resources within an AWS account. The rule can target one or more Regions and optionally configure a destination (such as CloudWatch Logs or S3) along with source-specific parameters for VPC flow logs, WAF logs, CloudTrail events, ELB access logs, and more. * * > **NOTE:** Before using this resource, telemetry evaluation must be enabled for your AWS account. Use the `aws.observabilityadmin.TelemetryEvaluation` resource to enable it. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluation("example", {}); * const exampleTelemetryRule = new aws.observabilityadmin.TelemetryRule("example", { * rule: { * telemetryType: "Logs", * resourceType: "AWS::EC2::VPC", * }, * ruleName: "example-telemetry-rule", * }, { * dependsOn: [example], * }); * ``` * * ### VPC Flow Logs to CloudWatch Logs * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluation("example", {}); * const exampleTelemetryRule = new aws.observabilityadmin.TelemetryRule("example", { * rule: { * destinationConfiguration: { * vpcFlowLogParameters: { * trafficType: "ALL", * maxAggregationInterval: 60, * }, * destinationType: "cloud-watch-logs", * destinationPattern: "/aws/vpcflowlogs/", * retentionInDays: 30, * }, * telemetryType: "Logs", * resourceType: "AWS::EC2::VPC", * telemetrySourceTypes: ["VPC_FLOW_LOGS"], * allRegions: true, * allowFieldUpdates: true, * }, * ruleName: "vpc-flow-logs-rule", * }, { * dependsOn: [example], * }); * ``` * * ### Replicated Across Specific Regions * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluation("example", {}); * const exampleTelemetryRule = new aws.observabilityadmin.TelemetryRule("example", { * rule: { * telemetryType: "Logs", * resourceType: "AWS::EKS::Cluster", * regions: [ * "us-east-1", * "us-west-2", * "eu-west-1", * ], * }, * ruleName: "multi-region-rule", * }, { * dependsOn: [example], * }); * ``` * * ### WAF Logging with Filters and Redacted Fields * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluation("example", {}); * const exampleTelemetryRule = new aws.observabilityadmin.TelemetryRule("example", { * rule: { * destinationConfiguration: { * wafLoggingParameters: { * loggingFilter: { * filters: [{ * conditions: [{ * actionCondition: { * action: "ALLOW", * }, * }], * behavior: "DROP", * requirement: "MEETS_ANY", * }], * defaultBehavior: "KEEP", * }, * redactedFields: [{ * singleHeader: { * name: "authorization", * }, * queryString: "", * }], * logType: "WAF_LOGS", * }, * destinationType: "cloud-watch-logs", * destinationPattern: "aws-waf-logs-", * retentionInDays: 30, * }, * telemetryType: "Logs", * resourceType: "AWS::WAFv2::WebACL", * }, * ruleName: "waf-logs-rule", * }, { * dependsOn: [example], * }); * ``` * * ### With Tags * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluation("example", {}); * const exampleTelemetryRule = new aws.observabilityadmin.TelemetryRule("example", { * rule: { * telemetryType: "Logs", * resourceType: "AWS::EC2::VPC", * }, * ruleName: "tagged-rule", * tags: { * Environment: "production", * Purpose: "monitoring", * }, * }, { * dependsOn: [example], * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `ruleName` (String) Name of the telemetry rule. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import CloudWatch Observability Admin Telemetry Rules using `ruleName`. For example: * * ```sh * $ pulumi import aws:observabilityadmin/telemetryRule:TelemetryRule example example-telemetry-rule * ``` */ export declare class TelemetryRule extends pulumi.CustomResource { /** * Get an existing TelemetryRule resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: TelemetryRuleState, opts?: pulumi.CustomResourceOptions): TelemetryRule; /** * Returns true if the given object is an instance of TelemetryRule. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is TelemetryRule; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Configuration block for the telemetry rule. See `rule` below. */ readonly rule: pulumi.Output; /** * ARN of the telemetry rule. */ readonly ruleArn: pulumi.Output; /** * Name of the telemetry rule. Must be between 1 and 100 characters and contain only alphanumeric characters, hyphens, underscores, periods, hash symbols, and forward slashes. Changing this argument forces a new resource to be created. * * The following arguments are optional: */ readonly ruleName: pulumi.Output; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; readonly timeouts: pulumi.Output; /** * Create a TelemetryRule resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: TelemetryRuleArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering TelemetryRule resources. */ export interface TelemetryRuleState { /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration block for the telemetry rule. See `rule` below. */ rule?: pulumi.Input; /** * ARN of the telemetry rule. */ ruleArn?: pulumi.Input; /** * Name of the telemetry rule. Must be between 1 and 100 characters and contain only alphanumeric characters, hyphens, underscores, periods, hash symbols, and forward slashes. Changing this argument forces a new resource to be created. * * The following arguments are optional: */ ruleName?: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a TelemetryRule resource. */ export interface TelemetryRuleArgs { /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration block for the telemetry rule. See `rule` below. */ rule: pulumi.Input; /** * Name of the telemetry rule. Must be between 1 and 100 characters and contain only alphanumeric characters, hyphens, underscores, periods, hash symbols, and forward slashes. Changing this argument forces a new resource to be created. * * The following arguments are optional: */ ruleName: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } //# sourceMappingURL=telemetryRule.d.ts.map