All Apps and Add-ons

How to stream AWS Lambda logs to Splunk ?

ivaylosharkov
New Member

I'm trying to stream AWS Lamda logs to Splunk following the [walk-trough][1]

Looking at the Splunk "myLambdaTrigger" logs I see the Splunk server accepted the data generated by my Lambda called "generateId"

Unfortunately I'm not able to find any traces in my Splunk Enterprise instance

START RequestId: cf05d3b8-714f-11e7-809c-df386ce7ac4a Version: $LATEST
2017-07-25T15:42:04.917Z cf05d3b8-714f-11e7-809c-df386ce7ac4a Event Data:
{
"messageType": "DATA_MESSAGE",
"owner": "524115710791",
"logGroup": "/aws/lambda/generateId",
"logStream": "2017/07/25/[$LATEST]d52f089786df4e7485ce7b3f2b113f9e",
"subscriptionFilters": [
"myLambdaTrigger"
],
"logEvents": [
{
"id": "33473358868028975175591691895812150494582623679244730368",
"timestamp": 1500997324082,
"message": "START RequestId: ce9b78a6-714f-11e7-8ed1-6b7b08305660 Version: $LATEST\n"
}
]
}

2017-07-25T15:42:04.931Z cf05d3b8-714f-11e7-809c-df386ce7ac4a Sending event
2017-07-25T15:42:04.933Z cf05d3b8-714f-11e7-809c-df386ce7ac4a Response received
2017-07-25T15:42:04.933Z cf05d3b8-714f-11e7-809c-df386ce7ac4a Sent
2017-07-25T15:42:04.933Z cf05d3b8-714f-11e7-809c-df386ce7ac4a Response from Splunk:
{
"text": "Success",
"code": 0
}

2017-07-25T15:42:04.933Z cf05d3b8-714f-11e7-809c-df386ce7ac4a Successfully processed 1 log event(s).
END RequestId: cf05d3b8-714f-11e7-809c-df386ce7ac4a
REPORT RequestId: cf05d3b8-714f-11e7-809c-df386ce7ac4a Duration: 16.41 ms Billed Duration: 100 ms Memory Size: 512 MB Max Memory Used: 25 MB

0 Karma

soumyasaha25
Contributor

Hi, were you able to figure out the issue. Do you mind sharing your insights, since its quite sometime that you had posted this question and might have figured out a solution of it.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...