Hi All,
I am trying to parse Amazon Cloudtrail logs to Elasticsearch using logstash. I have my s3 plugin configured and output been set to Elasticsearch but i find out that there is no grok pattern defined as to pass the logs to Elasticsearch.
Has anyone been able to successfully ingest cloudtrail logs with logstash.
I had a look at the post Cloudtrail Codec but that surely didn't help. The installation is never successful.
I am currently using ES 5.2 with Logstash 5.2.
Help!!!
--
Niraj