Hi Splunkers,
I have to create an alert when there is a root user login in AWS. For this, I am ingesting cloudtrail logs to distributed splunk env. I want to add organization wide aws accounts to get logs. Adding every single account and creds in Splunk add-on for AWS is difficult. Kindly suggest a way to onboard cloudtrail logs from multiple accounts.
Thanks