Getting Data In

How to log Cloudtrail logs from multiple AWS accounts?

akasmika
Loves-to-Learn

Hi Splunkers,

I have to create an alert when there is a root user login in AWS. For this, I am ingesting cloudtrail logs to distributed splunk env. I want to add organization wide aws accounts to get logs. Adding every single account and creds in Splunk add-on for AWS is difficult. Kindly suggest a way to onboard cloudtrail logs from multiple accounts.

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...