All Apps and Add-ons

SQS-Based-S3 Input for Cloudtrail - Does it support "blacklist" and "Exclude describe events" ?

deepamshah
Explorer

Hi,

I am using SQS-Based-S3 Inputs (multiple inputs retrieving from the queue) to ingest CloudTrail data. The documentation says the standard input supports exclude_describe_events and blacklist to filter out unwanted events. Just wondering if the same is supported when its a SQS Based S3 Input .  Note: Currently I am using PROPS/REGEX to exclude events but got it working only after a few attempts (after a few rounds of errors about MATCH_LIMIT being exceeded. 

Thanks

Labels (3)
0 Karma

rahul_jasrotia
Path Finder

Hi @deepamshah ,

Did you get a solution to this?

 

Also how did you achieve it using props/regex?

I am looking to ignore some Cloudtrail events too from S3 bucket but blacklist isn't working like mentioned.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...