Prometheus exporter for AWS GuardDuty
Features
- Exports the number of current (unarchived) findings from AWS GuardDuty, splitted by region and severity
- Supports multiple AWS regions
Exported metrics
The exporter exports the following metrics:
| Metric name | Type | Labels | Description |
|---|---|---|---|
aws_guardduty_exporter_up |
gauge | None | Always 1: can be used to check if it's running |
aws_guardduty_current_findings |
gauge | region, severity |
The current number of unarchived findings |
aws_guardduty_scrape_errors_total |
counter | region, severity |
The total number of scrape errors |
How to run it
You have two options to run it:
-
Manually install and run the
prometheus-aws-guardduty-exporterPython packagepip3 install prometheus-aws-guardduty-exporter prometheus-aws-guardduty-exporter --region us-east-1 -
Use the Docker image available on Docker hub
docker run --env AWS_ACCESS_KEY_ID="id" --env AWS_SECRET_ACCESS_KEY="secret" spreaker/prometheus-aws-guardduty-exporter --region us-east-1
The cli supports the following arguments:
| Argument | Required | Description |
|---|---|---|
--region REGION [REGION ...] |
yes | AWS GuardDuty region (can specify multiple space separated regions) |
--role-arn |
The ARN of an AWS role to assume | |
--exporter-host |
The host at which the Prometheus exporter should listen to. Defaults to 127.0.0.1 |
|
--exporter-port |
The port at which the Prometheus exporter should listen to. Defaults to 9100 |
|
--log-level LOG_LEVEL |
Minimum log level. Accepted values are: DEBUG, INFO, WARNING, ERROR, CRITICAL. Defaults to INFO |
Required IAM privileges
In order to successfully run, this application requires the following IAM privileges:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ListDetectorsAndGetFindingsStatisticsInAnyRegion",
"Effect": "Allow",
"Action": [
"guardduty:ListDetectors",
"guardduty:GetFindingsStatistics"
],
"Resource": "*"
}
]
}
Development
Run the development environment:
docker-compose build dev && docker-compose run --rm dev
Run tests in the dev environment:
python3 -m unittest
License
This software is released under the MIT license.
Metadata
Release files for prometheus-aws-guardduty-exporter 3.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| prometheus_aws_guardduty_exporter-3.0.0.tar.gz | 7.1 kB | Details |
Release files / prometheus_aws_guardduty_exporter-3.0.0.tar.gz
| Download URL | prometheus_aws_guardduty_exporter-3.0.0.tar.gz |
|---|---|
| Size | 7.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a4c17e534e067e78330ff497078b5f8c1ae44780171bfd8346b05be6dea92d53
|
|
BLAKE2b-256 checksum How to use checksums |
40eb4e6eb306f64b5f598488bde3f6f49614675235083c635c5f95d294868f56
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.1.0 CPython/3.12.4
|