Getting Data In

Filter AWS Cloudtrail readonly events

ColinJacksonPS
Path Finder

Does anybody know a good way to filter out AWS Cloudtrail readonly events?

 

This is what I have on my HF and jumping through hoops to get this on the IDM for Splunk Cloud.

 

[cloudtrail_read_only]
REGEX = "^Describe|Get|List\p{Lu}|LookupEvents"
DEST_KEY = queue
FORMAT = nullQueue


and this to props.conf:

[aws:cloudtrail]
#Strip out readOnly AWS events (i.e. Describe*, List*)
TRANSFORMS-cloudtrail_read_only = cloudtrail_read_only

 

Doesn't seem to be filtering. Thoughts?

Labels (2)
Tags (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @ColinJacksonPS 

You can try following to send readOnly them to nullQueue. the REGEX matches "readOnly' = true in every event and if it find a match then those events won't be indexed. So make sure the readOnly events containing the operations/eventNAme that you do not want to index.

aws:cloudtrail is a default sourcetype when you set this in props.conf it applies to everything at platform level, instead if you want to limit to particular source/host use source:: , host:: type stanzas as provided here in example.

#props.conf
[your_sourcetype/source::<source>/host::<hostname>]
TRANSFORMS-nullq= setreadonlytonullQ
 
#transforms.conf
[setreadonlytonullQ]
REGEX = \"readOnly\"\:\s+true
DEST_KEY = queue
FORMAT = nullQueue

 ----

An upvote would be appreciated and accept solutions if it helps!

venkatasri
SplunkTrust
SplunkTrust

@ColinJacksonPS Appreciate if you could accept the solution. Hope it helped for your case.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @ColinJacksonPS 

Can you share sample event how it looks like covering Get*, List*, LookupEvents etc.. I am sure they don not start at very beginning of event since you mentioned ^ in regex which indicates very beginning of event.  REGEX shall be changed to match with event.

0 Karma

ColinJacksonPS
Path Finder

Here's what I can share. If this is working, readOnly=true should return no results, or at least those listed.  Raw, JSON formatted, and simple stats output. 

Screen Shot 2021-06-23 at 9.27.21 PM.pngScreen Shot 2021-06-23 at 9.26.57 PM.pngScreen Shot 2021-06-23 at 9.27.11 PM.png

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...