# AWS Cross Account Cloudtrails Parsing

**URL:** <https://community.graylog.org/t/aws-cross-account-cloudtrails-parsing/1216>\
**Category:** Graylog Add-ons\
**Created:** [May 23, 2017, 2:50pm UTC](https://community.graylog.org/t/aws-cross-account-cloudtrails-parsing/1216 "2017-05-23T14:50:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![SnazzyBootMan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/snazzybootman/32/8392_2.png) [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Post date:** [May 23, 2017, 2:50pm UTC](https://community.graylog.org/t/aws-cross-account-cloudtrails-parsing/1216/1 "2017-05-23T14:50:37Z")

</div>

So I have multiple AWS accounts and have turned on CloudTrail in each account.

Using cross account permissions I gather all of these events in a central account which has a GrayLog server. This server has the AWS Plugin configured for CloudTrail and happily ingests events from six or so AWS accounts.

The question I have is how do I tell which account each event is coming from? I wanted to split these into account specific streams but I can’t seem to see a unique field. The events seem to differ for different AWS services which makes it difficult to lock down to a specific account. Has anyone else come across this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 6, 2017, 3:12pm UTC](https://community.graylog.org/t/aws-cross-account-cloudtrails-parsing/1216/3 "2017-06-06T15:12:01Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
