CloudTrail and Security Analytics

I am ingesting CloudTrail logs from an SQS queue and after adding a few processors like the geoip processor it fails to even list fields like EventName for the Security Mappings let alone even automatically fill them.

Even before that, it did populate, but it would still give me an invalid field mapping error when I went to try and create the Detector. What is going on?