Does anybody know a good way to filter out AWS Cloudtrail events? I'd like to send to null queue events that contains eventType=AwsApiCall.
My input is configured as "Generic S3" (https://docs.splunk.com/Documentation/AddOns/released/AWS/S3)
This is what I have on my HF where the Splunk_TA_AWS is installed and configured:
transforms.conf
[eliminate-AwsApiCall]
REGEX = \"eventType\":\s+\"AwsApiCall\"
DEST_KEY = queue
FORMAT = nullQueue
props.conf:
[aws:cloudtrail]
TRANSFORMS-eliminate-AwsApiCall = eliminate-AwsApiCall
Doesn't seem to be filtering ... any thoughts?
Thanks
Marta