Fix AWS S3 Access Log Date to be ISO Compliant

When trying to use Sigma against S3 access logs there is an issue because of the date format that AWS uses for the logs.

The time at which the request was received; these dates and times are in Coordinated Universal time (UTC). The format, using strftime() terminology, is as follows: [%d/%b/%Y:%H:%M:%S %z]

[06/Feb/2019:00:00:38 +0000]

1 Like

Per @SigmaRoss:

To put the date in a compatible format use the following function:

DateTrunc(“hour”, CallDatetime(“try_to_timestamp”, [COLUMN/TIME], “[DD/MON/YYYY:HH24:MI:SS +0000]”))

Credit: Don H.