简介
本文档介绍如何解决Umbrella日志到Amazon S3存储桶的失败上传。
先决条件
在集成Umbrella以将日志上传到私有Amazon S3存储桶时,请确保以同时满足以下两个要求的存储桶为目标:
- AWS租户中存在存储桶。
- Umbrella有权上传到存储桶。
如何在AWS中配置存储桶策略
在创建桶时,可以使用JSON在AWS中的目标桶上配置桶策略。请注意,如果“bucketname”为(4个位置),则必须将其替换为实际的bucket名称。
{
"Version": "2008-10-17",
"Statement": [
{
"Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::bucketname/*"
},
{
"Sid": "",
"Effect": "Deny",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucketname/*"
},
{
"Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:GetBucketLocation",
"Resource": "arn:aws:s3:::bucketname"
},
{ "Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::bucketname"
}
]
}
有关配置Umbrella日志上传到专用AWS S3存储桶的完整详细信息,请参阅Umbrella文档。