All Apps and Add-ons

Filter information to another index

thomastaylor
Communicator

Hello all!

I just have a quick question regarding how to filter aws:cloudtrail logs from one index to another, or potentially filter the information before index time. We have an SQS Queue in one account that collects all the logs from other AWS accounts. Although this makes it easier on our end, this makes it so that the aws:cloudtrail logs are all indexed into one index; however, the content within the queues may contain information from all the different accounts-- i.e. PROD, QA, DEV, etc.

So, we have indexes setup for PROD, QA, and DEV (that collects aws:description logs)... but then another that collects all three environments' cloudtrail logs. Is there a way to setup some type of pre-index time filtering so that the logs can be moved into their appropriate index?

Ex.
companyname_aws_prod
companyname_aws_qa
companyname_aws_dev
companyname_aws_cloudtrail (But contains information for all three environments?)

Ideally, we don't want to keep a "cloudtrail" index because we don't want developers viewing logs from environments they don't have access too.

Any response would be greatly appreciated!

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...