x-pack/filebeat/module/aws/cloudtrail/README.md
Module for AWS CloudTrail logs which captures information about actions taken by a user, role or an AWS service. Events include actions taken in the AWS Management Console, AWS Command Line interface and AWS SDKs and APIs. These logs can help with:
Implementation based on the description of CloudTrail from the documentation that can be found in:
It should be noted that the cloudtrail fileset does not read the
CloudTrail Digest files that are delivered to the S3 bucket when Log
File Integrity is turned on, it only reads the CloudTrail logs.
filebeat.modules:
- module: aws
cloudtrail:
enabled: true
var.queue_url: <queue url>
var.credential_profile_name: <profile name>