<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to store logs to AWS S3 bucket with the hostname using Splunk Ingest actions in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709639#M29109</link>
    <description>&lt;P&gt;If I recall correctly there was same questions some time ago, but I cannot found it now.&lt;/P&gt;&lt;P&gt;Anyhow the answer was same on that time too.&lt;/P&gt;&lt;P&gt;Maybe you can use the next solutions as a work around?&lt;/P&gt;&lt;P&gt;Is it possible that you will change sourcetype to be e.g. &amp;lt;host&amp;gt;:&amp;lt;original sourcetype&amp;gt; for those events which you are forwarding to AWS's S3 buckets? In that way you full will your requirements to store those based on hostname?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 22:42:29 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-01-23T22:42:29Z</dc:date>
    <item>
      <title>How to store logs to AWS S3 bucket with the hostname using Splunk Ingest actions</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/708337#M29019</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are utilizing Splunk Ingest actions to copy data to an S3 bucket. After reviewing various articles and conducting some tests, I've successfully forwarded data to the S3 bucket, where it's currently being stored with the Sourcetype name. However, there's a requirement to store these logs using the hostname instead of the Sourcetype for improved visibility and operational efficiency. Although there isn't a direct method to accomplish this through the Ingest actions GUI, I believe it can be achieved using props and transforms. Can someone assist me with this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 11:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/708337#M29019</guid>
      <dc:creator>Richy_s</dc:creator>
      <dc:date>2025-01-09T11:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to store logs to AWS S3 bucket with the hostname using Splunk Ingest actions</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709553#M29106</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269413"&gt;@Richy_s&lt;/a&gt;- There is currently no option for it I think.&lt;/P&gt;&lt;P&gt;But you can suggest Splunk team to include it for future release of Splunk at &lt;A href="https://ideas.splunk.com/" target="_blank"&gt;https://ideas.splunk.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote if it does!!!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 06:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709553#M29106</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-01-23T06:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to store logs to AWS S3 bucket with the hostname using Splunk Ingest actions</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709639#M29109</link>
      <description>&lt;P&gt;If I recall correctly there was same questions some time ago, but I cannot found it now.&lt;/P&gt;&lt;P&gt;Anyhow the answer was same on that time too.&lt;/P&gt;&lt;P&gt;Maybe you can use the next solutions as a work around?&lt;/P&gt;&lt;P&gt;Is it possible that you will change sourcetype to be e.g. &amp;lt;host&amp;gt;:&amp;lt;original sourcetype&amp;gt; for those events which you are forwarding to AWS's S3 buckets? In that way you full will your requirements to store those based on hostname?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 22:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709639#M29109</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-23T22:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to store logs to AWS S3 bucket with the hostname using Splunk Ingest actions</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709684#M29110</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I raised a case with Splunk support and they confirm they do not have such capability in place and I advised the to add it to their future enhancements list.&amp;nbsp; I hope this will be considered.&amp;nbsp; Appreciate your response.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 13:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709684#M29110</guid>
      <dc:creator>Richy_s</dc:creator>
      <dc:date>2025-01-24T13:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to store logs to AWS S3 bucket with the hostname using Splunk Ingest actions</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709685#M29111</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently using Splunk ingest actions feature to route the logs to S3 bucket and it doesn't have the capability to include &amp;lt;host&amp;gt;:&amp;lt;original sourcetype&amp;gt; for the events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for taking time to reply to my query.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 13:52:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-store-logs-to-AWS-S3-bucket-with-the-hostname-using/m-p/709685#M29111</guid>
      <dc:creator>Richy_s</dc:creator>
      <dc:date>2025-01-24T13:52:56Z</dc:date>
    </item>
  </channel>
</rss>

