I'm using Add-on for Amazon Web Services version 5.0.0.
I have ingested ALB logs as described in https://docs.splunk.com/Documentation/AddOns/released/AWS/IncrementalS3.
Now I could see the logs are being indexed. However, those events still not parsing correctly. still I could see only the raw logs.
Is there anyone who could successfully parse the AWS ALB logs? I'm using Index cluster.
I have followed the below thread, though it is bit old. Still no luck.