All Apps and Add-ons

SQS-Based-S3 Input for Cloudtrail - Does it support "blacklist" and "Exclude describe events" ?

deepamshah
Explorer

Hi,

I am using SQS-Based-S3 Inputs (multiple inputs retrieving from the queue) to ingest CloudTrail data. The documentation says the standard input supports exclude_describe_events and blacklist to filter out unwanted events. Just wondering if the same is supported when its a SQS Based S3 Input .  Note: Currently I am using PROPS/REGEX to exclude events but got it working only after a few attempts (after a few rounds of errors about MATCH_LIMIT being exceeded. 

Thanks

Labels (3)
0 Karma

rahul_jasrotia
Path Finder

Hi @deepamshah ,

Did you get a solution to this?

 

Also how did you achieve it using props/regex?

I am looking to ignore some Cloudtrail events too from S3 bucket but blacklist isn't working like mentioned.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...