All Apps and Add-ons

Filter information to another index

thomastaylor
Communicator

Hello all!

I just have a quick question regarding how to filter aws:cloudtrail logs from one index to another, or potentially filter the information before index time. We have an SQS Queue in one account that collects all the logs from other AWS accounts. Although this makes it easier on our end, this makes it so that the aws:cloudtrail logs are all indexed into one index; however, the content within the queues may contain information from all the different accounts-- i.e. PROD, QA, DEV, etc.

So, we have indexes setup for PROD, QA, and DEV (that collects aws:description logs)... but then another that collects all three environments' cloudtrail logs. Is there a way to setup some type of pre-index time filtering so that the logs can be moved into their appropriate index?

Ex.
companyname_aws_prod
companyname_aws_qa
companyname_aws_dev
companyname_aws_cloudtrail (But contains information for all three environments?)

Ideally, we don't want to keep a "cloudtrail" index because we don't want developers viewing logs from environments they don't have access too.

Any response would be greatly appreciated!

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...