Skip to main content
Solved

For CloudTrail, how would I format a query to look for the follow pattern?

  • March 11, 2025
  • 4 replies
  • 3 views

Hello.  I have a basic CloudTrail bucket and would like to have the account number part of the bucket path be able to be specified in a Cribl Search.
How would I format a search query that looks for “account” 12345 if the path is as follows. …/AWSLogs/${account}/CloudTrail/…

Best answer by dritan

dataset=mydataset account=12345

4 replies

  • Employee
  • Answer
  • March 11, 2025

dataset=mydataset account=12345


  • Author
  • Employee
  • March 11, 2025

That's what I figured it would be, but wasn't seeing results. I let it run for 30 seconds this time and it showed results after I cancelled the search.


  • Employee
  • March 11, 2025

oh, maybe some ui refresh issues?


  • Author
  • Employee
  • March 11, 2025

It must have been, but It's working now. just taking a bit longer than I was allowing it to run.Thanks for helping confirm/sanity check for me :slightly_smiling_face: