All Apps and Add-ons

Filter information to another index

thomastaylor
Communicator

Hello all!

I just have a quick question regarding how to filter aws:cloudtrail logs from one index to another, or potentially filter the information before index time. We have an SQS Queue in one account that collects all the logs from other AWS accounts. Although this makes it easier on our end, this makes it so that the aws:cloudtrail logs are all indexed into one index; however, the content within the queues may contain information from all the different accounts-- i.e. PROD, QA, DEV, etc.

So, we have indexes setup for PROD, QA, and DEV (that collects aws:description logs)... but then another that collects all three environments' cloudtrail logs. Is there a way to setup some type of pre-index time filtering so that the logs can be moved into their appropriate index?

Ex.
companyname_aws_prod
companyname_aws_qa
companyname_aws_dev
companyname_aws_cloudtrail (But contains information for all three environments?)

Ideally, we don't want to keep a "cloudtrail" index because we don't want developers viewing logs from environments they don't have access too.

Any response would be greatly appreciated!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...