I’m total newbie to graylog. I have a central S3 bucket receiving cloudtrail logs from other accounts. I’m using sherzberg/graylog-plugin-s3 for fetching logs into graylog. An issue with cloudtrail logs is that it has multiple events combined. I want to separate each event into its own log entry in graylog and have it indexed. How can I achieve this?
I tried using the bundled aws plugin, for some reason its not working. Anyways i would need to figure out this since I have plans to fetch other types of logs from S3 too.
Thanks in advance.