All Apps and Add-ons

AWS Cloud Watch Metrics into Splunk Cloud

MatthewH007
Path Finder

I have read multiple threads about getting data into Splunk but just about every one is for Splunk on-prem and not Cloud. Right now, I get most of my data in using multiple HEC's (Http Event Collector) as well as Kineis Firehose via an HEC as well.

I would like to start off with getting ELB Metrics into Splunk and am looking for feedback as to the best way to get that data into Splunk. Should it be using the AWS add-on via a Heavy Forwarder? Somehow get the data into a Cloud Watch Log group (Maybe a Lambda Function) then forward with Kinesis Firehose to an HEC?

Any feedback on users who have done this or what Splunk recommends is now the best way of doing this would be greatly appreciated.

Tags (2)
0 Karma
1 Solution

klaxdal
Contributor

I would recommend HEC - Kinesis Firehose - I have implemented both .

As I understand it - the Heavy Forwader method with soon be deprecated.

View solution in original post

ahgfyvu
Observer

Thanks For Shere This Blog !!

0 Karma

klaxdal
Contributor

I would recommend HEC - Kinesis Firehose - I have implemented both .

As I understand it - the Heavy Forwader method with soon be deprecated.

MatthewH007
Path Finder

Ty for the answer. Apparently, Splunk still recommends doing it this way:
https://www.splunk.com/blog/2018/10/30/working-with-aws-cloudwatch-metrics.html

It is using a Heavy forwarder with the AWS Add-On and the 'Splunk Metrics Workspace' app.

0 Karma

klaxdal
Contributor

See the follwing :

Blockquote

Splunk strongly recommends against using the CloudWatch Logs inputs to collect VPC Flow Logs data (source type: aws:cloudwatchlogs:vpcflow) since the input type will be deprecated in upcoming releases. Configure Kinesis inputs to collect VPC Flow Logs instead. The add-on includes index-time logic to perform the correct knowledge extraction for these events through the Kinesis input as well.

Blockquote

https://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatchLogs

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...