Getting Data In

Cloudtrail JSON logs do not ingest into splunk in a usable manner. How to parse correctly?

thisissplunk
Builder

The cloudtrail event exports are in JSON with fields, which is great. However, each event has a top level empty piece to the structure that forces you to expand the entire event when looking at it in the gui (the + symbol). It also makes searching on fields incredibly difficult.

Is there some app or way to remove that parent level JSON bit with Splunk itself as it ingests? Currently we do it with a python script, but it takes forever to decompress, parse and the compress again.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...