AWS EC2 metadata

Parse metadata emitted by AWS EC2 instances

status: stable egress: stream state: stateless output: log

Requirements

Running this transform within Docker on EC2 requires 2 network hops. Users must raise this limit:

aws ec2 modify-instance-metadata-options --instance-id <ID> --http-endpoint enabled --http-put-response-hop-limit 2

Configuration

Example configurations

{
  "transforms": {
    "my_transform_id": {
      "type": "aws_ec2_metadata",
      "inputs": [
        "my-source-or-transform-id"
      ],
      "fields": [
        "instance-id"
      ],
      "namespace": null,
      "refresh_interval_secs": 10
    }
  }
}
[transforms.my_transform_id]
type = "aws_ec2_metadata"
inputs = [ "my-source-or-transform-id" ]
fields = [ "instance-id" ]
refresh_interval_secs = 10
---
transforms:
  my_transform_id:
    type: aws_ec2_metadata
    inputs:
      - my-source-or-transform-id
    fields:
      - instance-id
    namespace: null
    refresh_interval_secs: 10
{
  "transforms": {
    "my_transform_id": {
      "type": "aws_ec2_metadata",
      "inputs": [
        "my-source-or-transform-id"
      ],
      "endpoint": "http://169.254.169.254",
      "fields": [
        "instance-id"
      ],
      "namespace": null,
      "refresh_interval_secs": 10
    }
  }
}
[transforms.my_transform_id]
type = "aws_ec2_metadata"
inputs = [ "my-source-or-transform-id" ]
endpoint = "http://169.254.169.254"
fields = [ "instance-id" ]
refresh_interval_secs = 10
---
transforms:
  my_transform_id:
    type: aws_ec2_metadata
    inputs:
      - my-source-or-transform-id
    endpoint: http://169.254.169.254
    fields:
      - instance-id
    namespace: null
    refresh_interval_secs: 10

endpoint

optional string
Override the default EC2 Metadata endpoint.
default: http://169.254.169.254

fields

common optional [string]
A list of fields to include in each event.
Array string literal
Examples
[
  "instance-id",
  "local-hostname"
]
default: [instance-id local-hostname local-ipv4 public-hostname public-ipv4 ami-id availability-zone vpc-id subnet-id region]

inputs

required [string]

A list of upstream source or transform IDs. Wildcards (*) are supported but must be the last character in the ID.

See configuration for more info.

Array string literal
Examples
[
  "my-source-or-transform-id",
  "prefix-*"
]

namespace

common optional string
Prepend a namespace to each field’s key.

refresh_interval_secs

common optional uint
The interval in seconds at which the EC2 Metadata api will be called.
default: 10

Output

Logs

Log

Log event enriched with EC2 metadata
Fields
ami-id required string literal
The ami-id that the current EC2 instance is using.
Examples
ami-00068cd7555f543d5
availability-zone required string literal
The availability-zone that the current EC2 instance is running in.
Examples
54.234.246.107
instance-id required string literal
The instance-id of the current EC2 instance.
Examples
i-096fba6d03d36d262
local-hostname required string literal
The local-hostname of the current EC2 instance.
Examples
ip-172-31-93-227.ec2.internal
local-ipv4 required string literal
The local-ipv4 of the current EC2 instance.
Examples
172.31.93.227
public-hostname required string literal
The public-hostname of the current EC2 instance.
Examples
ec2-54-234-246-107.compute-1.amazonaws.com
public-ipv4 required string literal
The public-ipv4 of the current EC2 instance.
Examples
54.234.246.107
region required string literal
The region that the current EC2 instance is running in.
Examples
us-east-1
role-name required string literal
The role-name that the current EC2 instance is using.
Examples
some_iam_role
subnet-id required string literal
The subnet-id of the current EC2 instance’s default network interface.
Examples
subnet-9d6713b9
vpc-id required string literal
The vpc-id of the current EC2 instance’s default network interface.
Examples
vpc-a51da4dc

Telemetry

Metrics

link

events_in_total

counter
The number of events accepted by this component either from tagged origin like file and uri, or cumulatively from other origins.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.
container_name optional
The name of the container from which the event originates.
file optional
The file from which the event originates.
mode optional
The connection mode used by the component.
peer_addr optional
The IP from which the event originates.
peer_path optional
The pathname from which the event originates.
pod_name optional
The name of the pod from which the event originates.
uri optional
The sanitized URI from which the event originates.

events_out_total

counter
The total number of events emitted by this component.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.

metadata_refresh_failed_total

counter
The total number of failed efforts to refresh AWS EC2 metadata.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.

metadata_refresh_successful_total

counter
The total number of AWS EC2 metadata refreshes.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.

processed_bytes_total

counter
The number of bytes processed by the component.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.
container_name optional
The name of the container from which the bytes originate.
file optional
The file from which the bytes originate.
mode optional
The connection mode used by the component.
peer_addr optional
The IP from which the bytes originate.
peer_path optional
The pathname from which the bytes originate.
pod_name optional
The name of the pod from which the bytes originate.
uri optional
The sanitized URI from which the bytes originate.

processed_events_total

counter
The total number of events processed by this component. This metric is deprecated in place of using events_in_total and events_out_total metrics.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.

How it works

State

This component is stateless, meaning its behavior is consistent across each input.