Getting Data In

Filter AWS Cloudtrail AwsApiCall events?

martaBenedetti
Path Finder

Does anybody know a good way to filter out AWS Cloudtrail events? I'd like to send to null queue events that contains eventType=AwsApiCall.

My input is configured as "Generic S3" (https://docs.splunk.com/Documentation/AddOns/released/AWS/S3)

This is what I have on my HF where the Splunk_TA_AWS is installed and configured:

transforms.conf

 

[eliminate-AwsApiCall]
REGEX = \"eventType\":\s+\"AwsApiCall\"
DEST_KEY = queue
FORMAT = nullQueue

 


props.conf:

 

[aws:cloudtrail]
TRANSFORMS-eliminate-AwsApiCall = eliminate-AwsApiCall

 

 

Doesn't seem to be filtering ... any thoughts?

 

Thanks

Marta

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...