Replies: 3 comments
-
Step1: Create log source account assume role manually in your member-accountBelow is the details for this role. Please substitute the MAIN-ACCOUNT-ID with your main account ID and MEMBER-ACCOUNT-S3-BUCKET-NAME with your member account S3 bucket name before role creation. Note: By Trusted entity policy
Policies
Please copy and save this manually created role ARN, we will use it as a parameter during the pipeline stack deployment step. |
Beta Was this translation helpful? Give feedback.
-
Step2: Deploy the CloudTrail pipeline stack in your main account1. You can jump to the implementation guide through here.2. Select the correct template and click the template link.3. Fill in the CloudFormation template parameters.Please pay attention to the following parameters:
|
Beta Was this translation helpful? Give feedback.
-
Example of CloudFormation template input |
Beta Was this translation helpful? Give feedback.
-
Background: Customers do not want to deploy member account stack because it's their production account. They are aware of the Fluent Bit agent documentations and other cross-account roles that created by the member-account stack, which they do not need in CloudTrail ingestions.
Beta Was this translation helpful? Give feedback.
All reactions