<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cloudwatch logs tagging in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/743993#M118189</link>
    <description>&lt;P&gt;Expert advice needed.&lt;/P&gt;&lt;P&gt;I was able to ingest cloudwatch logs for ecs and lambda with data manager&lt;/P&gt;&lt;P&gt;Now i need to add tags like env= service= custom= to enrich logs&lt;/P&gt;&lt;P&gt;Same was done for metrics with otel collector flags and UF&lt;/P&gt;&lt;P&gt;For logs ingested with DM can i add aws resource tag to cloudwatch loggroup i'm ingesting and expect this tag (key-value pair) to be added to logs&lt;/P&gt;&lt;P&gt;Another possible solution could be to use splunk log driver directly from ecs instead of cloudwatch. Then according to documentation with&amp;nbsp;&lt;SPAN&gt;env flag of splunk log driver I should be able to add some container env to log message&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Same question for the lambdas.&lt;/P&gt;&lt;P&gt;But if only cloudwatch loggroup aws resource tags&amp;nbsp;from the loggroup are able to be attached to ingested message.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2025 19:22:38 GMT</pubDate>
    <dc:creator>okana</dc:creator>
    <dc:date>2025-04-10T19:22:38Z</dc:date>
    <item>
      <title>cloudwatch logs tagging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/743993#M118189</link>
      <description>&lt;P&gt;Expert advice needed.&lt;/P&gt;&lt;P&gt;I was able to ingest cloudwatch logs for ecs and lambda with data manager&lt;/P&gt;&lt;P&gt;Now i need to add tags like env= service= custom= to enrich logs&lt;/P&gt;&lt;P&gt;Same was done for metrics with otel collector flags and UF&lt;/P&gt;&lt;P&gt;For logs ingested with DM can i add aws resource tag to cloudwatch loggroup i'm ingesting and expect this tag (key-value pair) to be added to logs&lt;/P&gt;&lt;P&gt;Another possible solution could be to use splunk log driver directly from ecs instead of cloudwatch. Then according to documentation with&amp;nbsp;&lt;SPAN&gt;env flag of splunk log driver I should be able to add some container env to log message&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Same question for the lambdas.&lt;/P&gt;&lt;P&gt;But if only cloudwatch loggroup aws resource tags&amp;nbsp;from the loggroup are able to be attached to ingested message.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 19:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/743993#M118189</guid>
      <dc:creator>okana</dc:creator>
      <dc:date>2025-04-10T19:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: cloudwatch logs tagging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/744080#M118206</link>
      <description>&lt;P&gt;Assuming that you are able to edit the inputs.conf file, and that you have a definite value for env, service, and custom for each input stanza, then you could add meta tags to the input stanzas:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;_meta = env::&amp;lt;env value&amp;gt; service::&amp;lt;service value&amp;gt; custom::&amp;lt;custom value&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;I don't know if this works the same way with OTEL collectors.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Apr 2025 20:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/744080#M118206</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2025-04-13T20:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: cloudwatch logs tagging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/744096#M118213</link>
      <description>&lt;P&gt;In my case it is data manager or possibly lambda. There is no inputs.conf in both cases.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 08:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cloudwatch-logs-tagging/m-p/744096#M118213</guid>
      <dc:creator>okana</dc:creator>
      <dc:date>2025-04-14T08:25:50Z</dc:date>
    </item>
  </channel>
</rss>

