All Apps and Add-ons

Ia it possible to customize Splunk AWS Addon for Cloudwatch LOGS ?

skynt
Engager

HI,
I'm trying to create a stream for CloudWatch Logs under Splunk Cloud Web, but it is not streaming to the sourcetype/index i have setup. Found out under our Splunk HF, it's already streaming this CW Logs (from S3 directly), but with default configuration (index=aws sourcetype=aws:cloudwatchlogs <resource_id>), It's possible to customize it from the HF ? the "aws_cloudwatch_logs_tasks.conf" is empty. 

*OBS: From https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-some-AWS-CloudWatch-logs-not-appearing-... , @jzhong_splunk   answer, if using HF, i would need to raise ticket, why? 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...