Getting Data In

How to log Cloudtrail logs from multiple AWS accounts?

akasmika
Loves-to-Learn

Hi Splunkers,

I have to create an alert when there is a root user login in AWS. For this, I am ingesting cloudtrail logs to distributed splunk env. I want to add organization wide aws accounts to get logs. Adding every single account and creds in Splunk add-on for AWS is difficult. Kindly suggest a way to onboard cloudtrail logs from multiple accounts.

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...