Dashboards & Visualizations

AWS cloudtrail data

ezamit
Explorer

How can i take the eventName , instanceId and eventTime in a Pivot Table from the search below :

index=aws_cloudtrail sourcetype="aws:cloudtrail" (eventName="StartInstances" OR eventName="StopInstances" OR eventName="StartDBInstance" OR eventName="StopDBInstance" OR eventName="StartDBCluster" OR eventName="StopDBCluster") AND (userIdentity.type="AssumedRole" AND userIdentity.sessionContext.sessionIssuer.userName="*sched*") | spath "requestParameters.instancesSet.items{}.instanceId" | search "requestParameters.instancesSet.items{}.instanceId"="i-0486ba14134c4355b" | spath "responseElements.instancesSet.items{}.instanceId" | spath "recipientAccountId"

Events :

awsRegion: us-east-1
   eventCategory: Management
   eventID: 3a80a688-fa82-4950-b823-69ffc3283862
   eventName: StartInstances
   eventSource: ec2.amazonaws.com
   eventTime: 2024-01-30T11:00:38Z
   eventType: AwsApiCall
   eventVersion: 1.09
   managementEvent: true
   readOnly: false
   recipientAccountId: XXXXXXXXXXX
   requestID: b404437a-ee56-4531-842e-1b10c01f01d3
   requestParameters: { [-]
     instancesSet: { [-]
       items: [ [-]
         { [-]
           instanceIdi-0486ba14134c4355b
         }
       ]

     }

   }

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...