All Apps and Add-ons

Reading log files from Amazon S3

grahampoulter
Path Finder

We're considering Amazon Elastic Beanstalk. The application logs will get rotated to S3 buckets, so I'm asking if there is a Splunk app or other well-supported method to read logs from S3 into Splunk.

Tags (2)
1 Solution

khourihan_splun
Splunk Employee
Splunk Employee

You can try our S3 app here: http://apps.splunk.com/app/1137/

Or you can mount your S3 as a filesystem and have a Universal Forwarder monitor it like a directory. There is a good writeup here: http://www.reedmurphy.net/blog/post/splunking-through-amazon-s3-access-logs

I suggest going the s3cmd route, its a little more feature rich than the Splunk app, but I have used both with success.

View solution in original post

khourihan_splun
Splunk Employee
Splunk Employee

You can try our S3 app here: http://apps.splunk.com/app/1137/

Or you can mount your S3 as a filesystem and have a Universal Forwarder monitor it like a directory. There is a good writeup here: http://www.reedmurphy.net/blog/post/splunking-through-amazon-s3-access-logs

I suggest going the s3cmd route, its a little more feature rich than the Splunk app, but I have used both with success.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...