All Apps and Add-ons

AWS ELB logs not correctly parsing

krisrmal
Engager

Hi,

I'm using Add-on for Amazon Web Services version 5.0.0

I have ingested ALB logs as described in https://docs.splunk.com/Documentation/AddOns/released/AWS/IncrementalS3.

Now I could see the logs are being indexed. However, those events still not parsing correctly. still I could see only the raw logs.

Is there anyone who could successfully parse the AWS ALB logs? I'm using Index cluster. 

I have followed the below thread, though it is bit old. Still no luck. 

https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-are-A...

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...