Hello,
we configured a ClodTrail log source to collect logs from our customers'AWS instance; we do not use SQS queues but we pull them directly from bucket.
Customer is collecting logs from several AWS region in a single bucket (the bucket belongs to eu-west-1 region), each region has a subdirectory inside the bucket..for example we have:
....../CloudTrail/eu-central-1/2022/02/....
....../CloudTrail/ap-east-1/2022/02/...
If we configure directory prefix ...../CloudTrail/ and .* as file pattern, are we sure we are going to collect any file inside any subdirectory and so we get all the events?
If not, is there a way to collect all the files (in json.gz format) from any sudirectory inside a single directory prefix?
Thanks
Davide
#QRadar#Support#SupportMigration