簡介
本文檔介紹如何解決Umbrella日誌到Amazon S3儲存桶的失敗上傳。
必要條件
在整合Umbrella以將日誌上傳到私有Amazon S3儲存桶時,請確保以同時滿足以下兩個要求的儲存桶為目標:
- AWS租戶中存在儲存桶。
- Umbrella有權上傳到儲存桶。
如何在AWS中配置儲存桶策略
在建立儲存桶時,可以使用JSON在AWS中的目標儲存桶上配置儲存桶策略。請注意,任何位置的「bucketname」為(4位),都必須用桶的實際名稱替換。
{
"Version": "2008-10-17",
"Statement": [
{
"Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::bucketname/*"
},
{
"Sid": "",
"Effect": "Deny",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucketname/*"
},
{
"Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:GetBucketLocation",
"Resource": "arn:aws:s3:::bucketname"
},
{ "Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::568526795995:user/logs"
},
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::bucketname"
}
]
}
有關配置Umbrella日誌上傳到專用AWS S3儲存桶的完整詳細資訊,請參閱Umbrella文檔。