Step 3: Ingest AWS CloudTrail Logs
You can build a log analytics pipeline to ingest AWS CloudTrail logs.
Important
Make sure your CloudTrail and Centralized Logging with OpenSearch are in the same AWS Region.
- Sign in to the Centralized Logging with OpenSearch Console.
- In the navigation pane, select AWS Service Log Analytics Pipelines.
- Choose Create a log ingestion.
- In the AWS Services section, choose AWS CloudTrail.
- Choose Next.
- Under Specify settings, for Trail, select one from the dropdown list.
- Choose Next.
- In the Specify OpenSearch domain section, select the imported domain for Amazon OpenSearch domain.
- Choose Yes for Sample dashboard.
- Keep default values and choose Next.
- Choose Create.