I have an S3 bucket with a couple years worth of Cloudtrail logs. How can I onboard just the last 3 months of logs into Chronicle? According to
https://cloud.google.com/chronicle/docs/ingestion/ingest-aws-logs-into-chronicle
it seems I can append
{{datetime(yyyy/MM/dd)}}
to the url so that Chronicle would scan logs each time only for a particular day suggesting I can make it start ingesting from this point forward but I'd like some history.
How can I onboard just the last 3 months of logs from my S3 bucket into Chronicle?
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
