{
  "name": "aws_bedrock",
  "title": "Amazon Bedrock",
  "version": "1.6.0",
  "release": "ga",
  "description": "Collect Amazon Bedrock model invocation logs and runtime metrics with Elastic Agent.",
  "type": "integration",
  "download": "/epr/aws_bedrock/aws_bedrock-1.6.0.zip",
  "path": "/package/aws_bedrock/1.6.0",
  "icons": [
    {
      "src": "/img/icon.svg",
      "path": "/package/aws_bedrock/1.6.0/img/icon.svg",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.16.5 || ^9.0.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "aws",
    "cloud",
    "observability",
    "security"
  ],
  "signature_path": "/epr/aws_bedrock/aws_bedrock-1.6.0.zip.sig",
  "format_version": "3.0.2",
  "readme": "/package/aws_bedrock/1.6.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/aws_bedrock_invocation.png",
      "path": "/package/aws_bedrock/1.6.0/img/aws_bedrock_invocation.png",
      "title": "Runtime metrics",
      "size": "1518x873",
      "type": "image/png"
    },
    {
      "src": "/img/aws_bedrock_chat_image.png",
      "path": "/package/aws_bedrock/1.6.0/img/aws_bedrock_chat_image.png",
      "title": "Text and chat metrics",
      "size": "1489x645",
      "type": "image/png"
    },
    {
      "src": "/img/aws_bedrock_logs.png",
      "path": "/package/aws_bedrock/1.6.0/img/aws_bedrock_logs.png",
      "title": "Invocation logs",
      "size": "3688x2216",
      "type": "image/png"
    },
    {
      "src": "/img/amazon_bedrock_guardrails_overview.png",
      "path": "/package/aws_bedrock/1.6.0/img/amazon_bedrock_guardrails_overview.png",
      "title": "Guardrails Overview",
      "size": "1519x1003",
      "type": "image/png"
    },
    {
      "src": "/img/amazon_bedrock_guardrails_invocation_details.png",
      "path": "/package/aws_bedrock/1.6.0/img/amazon_bedrock_guardrails_invocation_details.png",
      "title": "Guardrails Overview",
      "size": "1545x1001",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/aws_bedrock/1.6.0/LICENSE.txt",
    "/package/aws_bedrock/1.6.0/changelog.yml",
    "/package/aws_bedrock/1.6.0/manifest.yml",
    "/package/aws_bedrock/1.6.0/validation.yml",
    "/package/aws_bedrock/1.6.0/docs/README.md",
    "/package/aws_bedrock/1.6.0/img/amazon_bedrock_guardrails_invocation_details.png",
    "/package/aws_bedrock/1.6.0/img/amazon_bedrock_guardrails_overview.png",
    "/package/aws_bedrock/1.6.0/img/aws_bedrock_chat_image.png",
    "/package/aws_bedrock/1.6.0/img/aws_bedrock_invocation.png",
    "/package/aws_bedrock/1.6.0/img/aws_bedrock_logs.png",
    "/package/aws_bedrock/1.6.0/img/icon.svg",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/manifest.yml",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/sample_event.json",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/manifest.yml",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/sample_event.json",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/manifest.yml",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/sample_event.json",
    "/package/aws_bedrock/1.6.0/kibana/dashboard/aws_bedrock-14fd745a-d3c1-4ebe-bd25-00b465336cde.json",
    "/package/aws_bedrock/1.6.0/kibana/dashboard/aws_bedrock-2a19b571-251b-487b-84b2-abd887efb8a4.json",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/fields/base-fields.yml",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/fields/ecs.yml",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/fields/fields.yml",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/fields/agent.yml",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/fields/base-fields.yml",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/fields/fields.yml",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/fields/input.yml",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/fields/base-fields.yml",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/fields/ecs.yml",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/fields/fields.yml",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/agent/stream/stream.yml.hbs",
    "/package/aws_bedrock/1.6.0/data_stream/guardrails/elasticsearch/ingest_pipeline/default.yml",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/agent/stream/aws-cloudwatch.yml.hbs",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/agent/stream/aws-s3.yml.hbs",
    "/package/aws_bedrock/1.6.0/data_stream/invocation/elasticsearch/ingest_pipeline/default.yml",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/agent/stream/stream.yml.hbs",
    "/package/aws_bedrock/1.6.0/data_stream/runtime/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "aws_bedrock",
      "title": "Amazon Bedrock",
      "description": "Collect Amazon Bedrock model invocation logs with Elastic Agent.",
      "inputs": [
        {
          "type": "aws-s3",
          "title": "Collect Logs from S3 Bucket",
          "description": "Collect bedrock logs from S3 bucket with Elastic Agent."
        },
        {
          "type": "aws-cloudwatch",
          "title": "Collect Logs from CloudWatch",
          "description": "Collect bedrock logs from CloudWatch with Elastic Agent."
        },
        {
          "type": "aws/metrics",
          "title": "Collect Amazon Bedrock metrics",
          "description": "Collect Amazon Bedrock metrics using AWS CloudWatch."
        }
      ],
      "multiple": true
    }
  ],
  "data_streams": [
    {
      "type": "metrics",
      "dataset": "aws_bedrock.guardrails",
      "title": "Amazon Bedrock Guardrails Metrics",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "aws/metrics",
          "vars": [
            {
              "name": "period",
              "type": "text",
              "title": "Collection Period",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "data_granularity",
              "type": "text",
              "title": "Data Granularity",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "regions",
              "type": "text",
              "title": "Regions",
              "multi": true,
              "required": false,
              "show_user": true
            },
            {
              "name": "latency",
              "type": "text",
              "title": "Latency",
              "description": "The 'latency' parameter adjusts the Metricbeat collection start and end times. AWS CloudWatch might experience delay in processing metrics for some services causing data points to be missed during the integration collection period. To mitigate this potential issue, specify a latency parameter such as `15m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags_filter",
              "type": "yaml",
              "title": "Tags Filter",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "# - key: \"created-by\"\n  # value: \"foo\"\n"
            },
            {
              "name": "include_linked_accounts",
              "type": "bool",
              "title": "Include Linked Accounts",
              "description": "When include_linked_accounts is set to true, CloudWatch metrics will be collected from both linked accounts and the monitoring account. Default is true.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": true
            },
            {
              "name": "owning_account",
              "type": "integer",
              "title": "Owning Account",
              "description": "Accepts an AWS account ID linked to the monitoring account. Works only if include_linked_accounts is set to true. If set, monitoring data will only include data from the given account.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the events are shipped. See [Processors](https://www.elastic.co/guide/en/fleet/current/elastic-agent-processor-configuration.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "stream.yml.hbs",
          "title": "Amazon Bedrock Guardrails metrics",
          "description": "Collect Amazon Bedrock Guardrails metrics",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "aws_bedrock",
      "elasticsearch": {
        "ingest_pipeline.name": "default"
      },
      "path": "guardrails"
    },
    {
      "type": "logs",
      "dataset": "aws_bedrock.invocation",
      "title": "Amazon Bedrock model invocation logs",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "aws-cloudwatch",
          "vars": [
            {
              "name": "log_group_arn",
              "type": "text",
              "title": "Log Group ARN",
              "description": "ARN of the log group to collect logs from.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "log_group_name",
              "type": "text",
              "title": "Log Group Name",
              "description": "Name of the log group to collect logs from. `region_name` is required when `log_group_name` is given.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "log_group_name_prefix",
              "type": "text",
              "title": "Log Group Name Prefix",
              "description": "The prefix for a group of log group names. `region_name` is required when `log_group_name_prefix` is given. `log_group_name` and `log_group_name_prefix` cannot be given at the same time.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "include_linked_accounts_with_prefix",
              "type": "bool",
              "title": "Include Linked Accounts with prefix",
              "description": "Include log groups from linked accounts when using `log_group_name_prefix` to derive the monitoring log groups.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "region_name",
              "type": "text",
              "title": "Region Name",
              "description": "Region that the specified log group or log group prefix belongs to.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "Number of Workers",
              "description": "The number of workers assigned to read from log groups. Each worker will read log events from one of the log groups matching `log_group_name_prefix`. For example, if `log_group_name_prefix` matches five log groups, then `number_of_workers` should be set to `5`. The default value is `1`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 1
            },
            {
              "name": "log_streams",
              "type": "text",
              "title": "Log Streams",
              "description": "A list of strings of log streams names that Filebeat collect log events from.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "log_stream_prefix",
              "type": "text",
              "title": "Log Stream Prefix",
              "description": "A string to filter the results to include only log events from log streams that have names starting with this prefix.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "start_position",
              "type": "text",
              "title": "Start Position",
              "description": "Specify whether the input should start reading logs from the `beginning` (oldest log entry), `end` (newest log entry), or `lastSync` (last successful read timestamp if input ran before).",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "beginning"
            },
            {
              "name": "scan_frequency",
              "type": "text",
              "title": "Scan Frequency",
              "description": "This config parameter sets how often Filebeat checks for new log events from the specified log group.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "api_timeput",
              "type": "text",
              "title": "API Timeout",
              "description": "The maximum duration of AWS API can take. If it exceeds the timeout, AWS API will be interrupted.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "api_sleep",
              "type": "text",
              "title": "API Sleep",
              "description": "This is used to sleep between AWS FilterLogEvents API calls inside the same collection period. `FilterLogEvents` API has a quota of 5 transactions per second (TPS)/account/Region. This value should only be adjusted when there are multiple Filebeats or multiple Filebeat inputs collecting logs from the same region and AWS account.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "200ms"
            },
            {
              "name": "latency",
              "type": "text",
              "title": "Latency",
              "description": "The amount of time required for the logs to be available to CloudWatch Logs. Sample values, `1m` or `5m` — see Golang [time.ParseDuration](https://pkg.go.dev/time#ParseDuration) for more details. Latency translates the query's time range to consider the CloudWatch Logs latency. Example: `5m` means that the integration will query CloudWatch to search for logs available 5 minutes ago.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": true,
              "default": [
                "forwarded"
              ]
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve Bedrock fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "aws-cloudwatch.yml.hbs",
          "title": "AWS logs via CloudWatch",
          "description": "Collect logs using aws-cloudwatch input.",
          "enabled": false,
          "ingestion_method": "AWS CloudWatch"
        },
        {
          "input": "aws-s3",
          "vars": [
            {
              "name": "api_timeout",
              "type": "text",
              "title": "API Timeout",
              "description": "The maximum duration of AWS API can take. The maximum is half of the visibility timeout value.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_arn",
              "type": "text",
              "title": "Bucket ARN",
              "description": "ARN of the AWS S3 bucket that will be polled for list operation. (Required when `queue_url`, `access_point_arn` and `non_aws_bucket_name` are not set).",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "access_point_arn",
              "type": "text",
              "title": "Access Point ARN",
              "description": "ARN of the AWS S3 Access Point that will be polled for list operation. (This is an alternative to the Bucket ARN, and required when `queue_url`, `bucket_arn` or `non_aws_bucket_name` are not set).",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[S3/SQS] Number of Workers",
              "description": "Number of workers that will process the S3 objects listed.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 1
            },
            {
              "name": "start_timestamp",
              "type": "text",
              "title": "Start Timestamp",
              "description": "If set, only read S3 objects with last modified timestamp newer than the given timestamp. Accepts a timestamp in `YYYY-MM-DDTHH:MM:SSZ` format. For example, \"2020-10-10T10:30:00Z\" (UTC) or \"2020-10-10T10:30:00Z+02:30\" (with zone offset).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_older",
              "type": "text",
              "title": "Ignore Older Timespan",
              "description": "If set, ignore S3 objects whose Last-Modified time is before the ignore older timespan. Timespan is checked from the current time to S3 object's Last-Modified time. Accepts a duration like `48h`, `2h30m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_list_interval",
              "type": "text",
              "title": "Bucket List Interval",
              "description": "Time interval for polling listing of the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "bucket_list_prefix",
              "type": "text",
              "title": "Bucket List Prefix",
              "description": "Prefix to apply for the list request to the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "buffer_size",
              "type": "text",
              "title": "Buffer Size",
              "description": "The size in bytes of the buffer that each harvester uses when fetching a file. This only applies to non-JSON logs.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "content_type",
              "type": "text",
              "title": "Content Type",
              "description": "A standard MIME type describing the format of the object data. This can be set to override the MIME type that was given to the object when it was uploaded. For example application/json.\n",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "encoding",
              "type": "text",
              "title": "Encoding",
              "description": "The file encoding to use for reading data that contains international characters. This only applies to non-JSON logs.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "expand_event_list_from_field",
              "type": "text",
              "title": "Expand Event List from Field",
              "description": "If the fileset using this input expects to receive multiple messages bundled under a specific field then the config option expand_event_list_from_field value can be assigned the name of the field. This setting will be able to split the messages under the group value into separate events. For example, CloudTrail logs are in JSON format and events are found under the JSON object \"Records\".\n",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "File Selectors",
              "description": "If the SQS queue will have events that correspond to files that this integration shouldn’t process file_selectors can be used to limit the files that are downloaded. This is a list of selectors which are made up of regex and expand_event_list_from_field options. The regex should match the S3 object key in the SQS message, and the optional expand_event_list_from_field is the same as the global setting. If file_selectors is given, then any global expand_event_list_from_field value is ignored in favor of the ones specified in the file_selectors. Regex syntax is the same as the Go language. Files that don’t match one of the regexes won’t be processed. content_type, parsers, include_s3_metadata,max_bytes, buffer_size, and encoding may also be set for each file selector.\n",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "fips_enabled",
              "type": "bool",
              "title": "Enable S3 FIPS",
              "description": "Enabling this option changes the service name from `s3` to `s3-fips` for connecting to the correct service endpoint.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "include_s3_metadata",
              "type": "text",
              "title": "Include S3 Metadata",
              "description": "This input can include S3 object metadata in the generated events for use in follow-on processing. You must specify the list of keys to include. By default none are included. If the key exists in the S3 response then it will be included in the event as aws.s3.metadata.<key> where the key name as been normalized to all lowercase.\n",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "max_bytes",
              "type": "text",
              "title": "Max Bytes",
              "description": "The maximum number of bytes that a single log message can have. All bytes after max_bytes are discarded and not sent. This setting is especially useful for multiline log messages, which can get large. This only applies to non-JSON logs.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "10MiB"
            },
            {
              "name": "max_number_of_messages",
              "type": "integer",
              "title": "Maximum Concurrent SQS Messages",
              "description": "Deprecated in agent version 8.16.0, this parameter is ignored if present, use number_of_workers instead. The maximum number of SQS messages that can be inflight at any time.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "non_aws_bucket_name",
              "type": "text",
              "title": "Non AWS Bucket Name",
              "description": "Name of the S3 bucket that will be polled for list operation. Required for 3rd party S3 compatible services. (Required when `queue_url`, `bucket_arn` or `access_point_arn` are not set).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "path_style",
              "type": "text",
              "title": "Path Style",
              "description": "Enabling this option sets the bucket name as a path in the API call instead of a subdomain. When enabled https://<bucket-name>.s3.<region>.<provider>.com becomes https://s3.<region>.<provider>.com/<bucket-name>. This is only supported with 3rd party S3 providers.  AWS does not support path style.\n",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "provider",
              "type": "text",
              "title": "Provider Name",
              "description": "Name of the 3rd party S3 bucket provider like backblaze or GCP.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "queue_url",
              "type": "text",
              "title": "Queue URL",
              "description": "URL of the AWS SQS queue that messages will be received from.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "sqs.max_receive_count",
              "type": "integer",
              "title": "SQS Message Maximum Receive Count",
              "description": "The maximum number of times a SQS message should be received (retried) before deleting it. This feature prevents poison-pill messages (messages that can be received but can’t be processed) from consuming resources.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "sqs.wait_time",
              "type": "text",
              "title": "SQS Maximum Wait Time",
              "description": "The maximum duration that an SQS `ReceiveMessage` call should wait for a message to arrive in the queue before returning. The maximum value is `20s`.\n",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "20s"
            },
            {
              "name": "visibility_timeout",
              "type": "text",
              "title": "Visibility Timeout",
              "description": "The duration that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.  The maximum is 12 hours.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": true,
              "default": [
                "forwarded"
              ]
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve Bedrock fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "aws-s3.yml.hbs",
          "title": "AWS logs from S3",
          "description": "Collect logs using aws-s3 input with or without SQS notification",
          "enabled": false,
          "ingestion_method": "AWS S3"
        }
      ],
      "package": "aws_bedrock",
      "path": "invocation"
    },
    {
      "type": "metrics",
      "dataset": "aws_bedrock.runtime",
      "title": "Amazon Bedrock Runtime Metrics",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "aws/metrics",
          "vars": [
            {
              "name": "period",
              "type": "text",
              "title": "Collection Period",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "data_granularity",
              "type": "text",
              "title": "Data Granularity",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "regions",
              "type": "text",
              "title": "Regions",
              "multi": true,
              "required": false,
              "show_user": true
            },
            {
              "name": "latency",
              "type": "text",
              "title": "Latency",
              "description": "The 'latency' parameter adjusts the Metricbeat collection start and end times. AWS CloudWatch might experience delay in processing metrics for some services causing data points to be missed during the integration collection period. To mitigate this potential issue, specify a latency parameter such as `15m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags_filter",
              "type": "yaml",
              "title": "Tags Filter",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "# - key: \"created-by\"\n  # value: \"foo\"\n"
            },
            {
              "name": "include_linked_accounts",
              "type": "bool",
              "title": "Include Linked Accounts",
              "description": "When include_linked_accounts is set to true, CloudWatch metrics will be collected from both linked accounts and the monitoring account. Default is true.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": true
            },
            {
              "name": "owning_account",
              "type": "integer",
              "title": "Owning Account",
              "description": "Accepts an AWS account ID linked to the monitoring account. Works only if include_linked_accounts is set to true. If set, monitoring data will only include data from the given account.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the events are shipped. See [Processors](https://www.elastic.co/guide/en/fleet/current/elastic-agent-processor-configuration.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "stream.yml.hbs",
          "title": "Amazon Bedrock metrics",
          "description": "Collect Amazon Bedrock metrics",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "aws_bedrock",
      "elasticsearch": {
        "ingest_pipeline.name": "default"
      },
      "path": "runtime"
    }
  ],
  "vars": [
    {
      "name": "shared_credential_file",
      "type": "text",
      "title": "Shared Credential File",
      "description": "Directory of the shared credentials file",
      "multi": false,
      "required": false,
      "show_user": false
    },
    {
      "name": "credential_profile_name",
      "type": "text",
      "title": "Credential Profile Name",
      "multi": false,
      "required": false,
      "show_user": false
    },
    {
      "name": "access_key_id",
      "type": "password",
      "title": "Access Key ID",
      "multi": false,
      "required": false,
      "show_user": true
    },
    {
      "name": "secret_access_key",
      "type": "password",
      "title": "Secret Access Key",
      "multi": false,
      "required": false,
      "show_user": true
    },
    {
      "name": "session_token",
      "type": "password",
      "title": "Session Token",
      "multi": false,
      "required": false,
      "show_user": true
    },
    {
      "name": "role_arn",
      "type": "text",
      "title": "Role ARN",
      "multi": false,
      "required": false,
      "show_user": false
    },
    {
      "name": "endpoint",
      "type": "text",
      "title": "Endpoint",
      "description": "URL of the entry point for an AWS web service",
      "multi": false,
      "required": false,
      "show_user": false,
      "default": ""
    },
    {
      "name": "default_region",
      "type": "text",
      "title": "Default AWS Region",
      "description": "Default region to use prior to connecting to region specific services/endpoints if no AWS region is set from environment variable, credentials or instance profile. If none of the above are set and no default region is set as well, `us-east-1` is used. A region, either from environment variable, credentials or instance profile or from this default region setting, needs to be set when using regions in non-regular AWS environments such as AWS China or US Government Isolated.",
      "multi": false,
      "required": false,
      "show_user": false,
      "default": ""
    },
    {
      "name": "proxy_url",
      "type": "text",
      "title": "Proxy URL",
      "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
      "multi": false,
      "required": false,
      "show_user": false
    }
  ]
}
