All Apps and Add-ons

SQS-Based-S3 Input for Cloudtrail - Does it support "blacklist" and "Exclude describe events" ?

deepamshah
Explorer

Hi,

I am using SQS-Based-S3 Inputs (multiple inputs retrieving from the queue) to ingest CloudTrail data. The documentation says the standard input supports exclude_describe_events and blacklist to filter out unwanted events. Just wondering if the same is supported when its a SQS Based S3 Input .  Note: Currently I am using PROPS/REGEX to exclude events but got it working only after a few attempts (after a few rounds of errors about MATCH_LIMIT being exceeded. 

Thanks

Labels (3)
0 Karma

rahul_jasrotia
Path Finder

Hi @deepamshah ,

Did you get a solution to this?

 

Also how did you achieve it using props/regex?

I am looking to ignore some Cloudtrail events too from S3 bucket but blacklist isn't working like mentioned.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...