Getting Data In

Filter AWS Cloudtrail AwsApiCall events?

martaBenedetti
Path Finder

Does anybody know a good way to filter out AWS Cloudtrail events? I'd like to send to null queue events that contains eventType=AwsApiCall.

My input is configured as "Generic S3" (https://docs.splunk.com/Documentation/AddOns/released/AWS/S3)

This is what I have on my HF where the Splunk_TA_AWS is installed and configured:

transforms.conf

 

[eliminate-AwsApiCall]
REGEX = \"eventType\":\s+\"AwsApiCall\"
DEST_KEY = queue
FORMAT = nullQueue

 


props.conf:

 

[aws:cloudtrail]
TRANSFORMS-eliminate-AwsApiCall = eliminate-AwsApiCall

 

 

Doesn't seem to be filtering ... any thoughts?

 

Thanks

Marta

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...