All Apps and Add-ons

Collect logs from all new CloudWatch Log Groups in AWS Add-on for Splunk?

HasterHerman
New Member

Hi everyone,

I’m currently collecting AWS CloudWatch logs from multiple accounts into a centralized logging account. However, new Log Groups are periodically created.

Is there a way to configure the Splunk Add-on for AWS so that it automatically collects logs from all existing and newly created CloudWatch Log Groups without having to manually add each one?

Any best practices or configuration tips would be greatly appreciated.

Thanks in advance!

Labels (3)
Tags (2)
0 Karma

thahir
Contributor

Hi @HasterHerman 

My suggestion is try to use the Generic S3 input in the Splunk Add-on for AWS, you can ingest logs collected from multiple AWS accounts sent to a central S3 bucket. The S3 bucket typically contains logs from different accounts and different CloudWatch log groups, organized via the S3 key/prefix convention (such as AWSLogs/<AccountID>/<log-group-name>/...). This allows you to pull and distinguish logs from various groups and accounts.

 

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...