All Apps and Add-ons

Filter information to another index

thomastaylor
Communicator

Hello all!

I just have a quick question regarding how to filter aws:cloudtrail logs from one index to another, or potentially filter the information before index time. We have an SQS Queue in one account that collects all the logs from other AWS accounts. Although this makes it easier on our end, this makes it so that the aws:cloudtrail logs are all indexed into one index; however, the content within the queues may contain information from all the different accounts-- i.e. PROD, QA, DEV, etc.

So, we have indexes setup for PROD, QA, and DEV (that collects aws:description logs)... but then another that collects all three environments' cloudtrail logs. Is there a way to setup some type of pre-index time filtering so that the logs can be moved into their appropriate index?

Ex.
companyname_aws_prod
companyname_aws_qa
companyname_aws_dev
companyname_aws_cloudtrail (But contains information for all three environments?)

Ideally, we don't want to keep a "cloudtrail" index because we don't want developers viewing logs from environments they don't have access too.

Any response would be greatly appreciated!

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!