Hi, wondering how to combine a text search field for easier searching through our cloudtrail logs in our ELK stack (5.3.0),
We'd like to have a search field called IAM-User = userIdentity.userName or userIdentity.sessionContext.sessionIssuer.userName or requestParameters.roleSessionName
Depending on which one has a value (exists), then search that field.
We're currently doing this :
type:cloudtrail AND (userIdentity.userName:"app-prod" OR userIdentity.sessionContext.sessionIssuer.userName:"app-prod" OR requestParameters.roleSessionName:"app-prod")
But this gets really tedious for searching through all our other users.