All Apps and Add-ons

SQS-Based-S3 Input for Cloudtrail - Does it support "blacklist" and "Exclude describe events" ?

deepamshah
Explorer

Hi,

I am using SQS-Based-S3 Inputs (multiple inputs retrieving from the queue) to ingest CloudTrail data. The documentation says the standard input supports exclude_describe_events and blacklist to filter out unwanted events. Just wondering if the same is supported when its a SQS Based S3 Input .  Note: Currently I am using PROPS/REGEX to exclude events but got it working only after a few attempts (after a few rounds of errors about MATCH_LIMIT being exceeded. 

Thanks

Labels (3)
0 Karma

rahul_jasrotia
Path Finder

Hi @deepamshah ,

Did you get a solution to this?

 

Also how did you achieve it using props/regex?

I am looking to ignore some Cloudtrail events too from S3 bucket but blacklist isn't working like mentioned.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...