All Apps and Add-ons

Reading log files from Amazon S3

grahampoulter
Path Finder

We're considering Amazon Elastic Beanstalk. The application logs will get rotated to S3 buckets, so I'm asking if there is a Splunk app or other well-supported method to read logs from S3 into Splunk.

Tags (2)
1 Solution

khourihan_splun
Splunk Employee
Splunk Employee

You can try our S3 app here: http://apps.splunk.com/app/1137/

Or you can mount your S3 as a filesystem and have a Universal Forwarder monitor it like a directory. There is a good writeup here: http://www.reedmurphy.net/blog/post/splunking-through-amazon-s3-access-logs

I suggest going the s3cmd route, its a little more feature rich than the Splunk app, but I have used both with success.

View solution in original post

khourihan_splun
Splunk Employee
Splunk Employee

You can try our S3 app here: http://apps.splunk.com/app/1137/

Or you can mount your S3 as a filesystem and have a Universal Forwarder monitor it like a directory. There is a good writeup here: http://www.reedmurphy.net/blog/post/splunking-through-amazon-s3-access-logs

I suggest going the s3cmd route, its a little more feature rich than the Splunk app, but I have used both with success.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...