<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk add-on for AWS: In a generic S3 input, can a key-prefix contain a wildcard? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489530#M136727</link>
    <description>&lt;P&gt;Did you resolve this? I have a similar issue trying to find the proper format for this field. Not sure if prefix means part of a file, or the folder within a bucket to be looking at....&lt;/P&gt;

&lt;P&gt;I have logs/ in that field, thinking that it is grabbing that folder but it is pulling hundreds of GB from S3, even though there are only 2GB worth of compressed log files in that folder...&lt;/P&gt;

&lt;P&gt;Hope you found something?&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2020 20:14:22 GMT</pubDate>
    <dc:creator>mpresseau</dc:creator>
    <dc:date>2020-01-13T20:14:22Z</dc:date>
    <item>
      <title>Splunk add-on for AWS: In a generic S3 input, can a key-prefix contain a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489528#M136725</link>
      <description>&lt;P&gt;Trying to use a key-prefix when setting up a Generic S3 input that utilizes a wildcard in the path, but it doesn't look to be working.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;S3 key prefix = /AWSLogs/*/vpcflowlogs/
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Has anyone had any luck in setting this up before?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 16:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489528#M136725</guid>
      <dc:creator>travislelledeep</dc:creator>
      <dc:date>2019-09-24T16:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for AWS: In a generic S3 input, can a key-prefix contain a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489529#M136726</link>
      <description>&lt;P&gt;Also to clarify - since it doesn't appear I can edit my post - this was setup via the GUI, so ignore the inputs.conf-like formatting of my example, since this wasn't setup in a .conf file, I was just representing what I used for my S3 key prefix.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 16:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489529#M136726</guid>
      <dc:creator>travislelledeep</dc:creator>
      <dc:date>2019-09-24T16:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for AWS: In a generic S3 input, can a key-prefix contain a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489530#M136727</link>
      <description>&lt;P&gt;Did you resolve this? I have a similar issue trying to find the proper format for this field. Not sure if prefix means part of a file, or the folder within a bucket to be looking at....&lt;/P&gt;

&lt;P&gt;I have logs/ in that field, thinking that it is grabbing that folder but it is pulling hundreds of GB from S3, even though there are only 2GB worth of compressed log files in that folder...&lt;/P&gt;

&lt;P&gt;Hope you found something?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 20:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/489530#M136727</guid>
      <dc:creator>mpresseau</dc:creator>
      <dc:date>2020-01-13T20:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for AWS: In a generic S3 input, can a key-prefix contain a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/537301#M151876</link>
      <description>&lt;P&gt;I'm trying to do the same thing. Anyone hear anything?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 20:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-add-on-for-AWS-In-a-generic-S3-input-can-a-key-prefix/m-p/537301#M151876</guid>
      <dc:creator>ColinJacksonPS</dc:creator>
      <dc:date>2021-01-26T20:47:56Z</dc:date>
    </item>
  </channel>
</rss>

