Hi!
My setup has a log archive account using AWS Landing zone where all the CloudTrail and VPC Flow Logs from multiple accounts get aggerated and stored in an s3 bucket. I want to send both of the logs to a Splunk HEC. Which is the best suited architecture pattern for this?
Hi @yackle_official! Thanks for checking in on Answers. Since this is an old post, I recommend starting a new thread with your question, so it can gain more current visibility.
Cheers!
-Kara D, Splunk Community Manager
Did you ever get an answer to this?