All Apps and Add-ons

Splunk Add-on for AWS for streaming cloudwatch logs

Aravind_1212
New Member

In the documentation at https://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatchLogs

we see below limitation. Can you please clarify on the same? Can't we use Splunk Add-on for AWS for streaming cloudwatch logs?

 

Due to rate limitations, don't use the Splunk Add-on for AWS to collect CloudWatch Log data which has the source type aws:cloudwatchlogs:*. Instead, use the Splunk Add-on for Amazon Kinesis Firehose to collect CloudWatch Log and VPC Flow Logs. The Spunk Add-on for Amazon Kinesis Firehose includes index-time logic to perform the correct knowledge extraction for these events through the Kinesis input as well.

Labels (1)
0 Karma

Aravind_1212
New Member

Please clarify on rate limitations.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...