All Apps and Add-ons

Filter information to another index

thomastaylor
Communicator

Hello all!

I just have a quick question regarding how to filter aws:cloudtrail logs from one index to another, or potentially filter the information before index time. We have an SQS Queue in one account that collects all the logs from other AWS accounts. Although this makes it easier on our end, this makes it so that the aws:cloudtrail logs are all indexed into one index; however, the content within the queues may contain information from all the different accounts-- i.e. PROD, QA, DEV, etc.

So, we have indexes setup for PROD, QA, and DEV (that collects aws:description logs)... but then another that collects all three environments' cloudtrail logs. Is there a way to setup some type of pre-index time filtering so that the logs can be moved into their appropriate index?

Ex.
companyname_aws_prod
companyname_aws_qa
companyname_aws_dev
companyname_aws_cloudtrail (But contains information for all three environments?)

Ideally, we don't want to keep a "cloudtrail" index because we don't want developers viewing logs from environments they don't have access too.

Any response would be greatly appreciated!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...