Complex query run over 4.5T of CloudTrail data-- jq + xargs (for parallelism) banged it out in under 4hrs #CommandLineSkillz
2
12
Highly recommend checking out Athena to query CT logs from S3. Exponential time savings and relatively cheap (as compared to using other services/methods). Even better time & cost savings w/ partition mgmt.
docs.aws.amazon.com/athena/l…
workshop.aws-management.tool…
wellarchitectedlabs.com/secu…
1
Well hello, Mr Fancypants! :-)
For reason's that don't bear discussing, I'm dealing with logs exported as JSON on disk.
Apr 15, 2021 · 10:14 PM UTC
1

