QUESTION

If I started with a single AWS CloudTrail source (📄 How do I add new AWS CloudTrail log sources to Panther when the original does not have a prefix?) which currently is not using a prefix, and now I want to add more, do I need to migrate the original source or create new prefixes for the new sources/"trails"?

ANSWER

There are multiple ways to add a new AWS CloudTrail log source when an existing source added to Panther lacks a prefix.

Options include the following:

 

You can also check our relevant article📄 How do I configure an S3 log source in Panther with a prefix exclusion or inclusion? for additional details on how to add prefixes and exclusion filters to your log sources.