Recommended method
EventBridge API Destinations — a CloudTrail-driven EventBridge rule delivers events to Bronto in real time over HTTPS, with no intermediate storage.Alternatives
- S3 Log Forwarder — CloudTrail’s native destination; the forwarder Lambda subscribes to the trail’s bucket and ships new objects.
- Kinesis Firehose — for very high event volumes. Enable Send to CloudWatch Logs on the trail, then add a subscription filter on the trail’s log group targeting a Firehose stream. CloudTrail events are JSON, so Bronto flattens them into searchable fields automatically — no parser needed.

