All Apps and Add-ons

Splunk App for AWS: How to configure the app with multiple AWS accounts?

blehnhar
New Member

I have cloudtrail logs for around 20 AWS accounts that I want to pull into Splunk. I'm using Splunk Web.

The way I'm doing this is to create a single bucket to store the cloudtrail logs and then a separate trail, sns topic, and sqs queue for each region in each account.

In Splunk, I create an input for each account and then add the sqs queue for each region to the input. That way I pull in separate SQS queues but they are still under one input.

In total, I'll have around 20 inputs for AWS if I do it this way. Should be this be fine in Splunk Web?

0 Karma

blehnhar
New Member

It seems like adding multiple accounts GREATLY increases cpu usage. Additional accounts seems to slow splunk web down considerably. I spun up a c4.2xlarge in AWS and The cpu is at almost 90% with 7 accounts added with cloudtrail inputs for each account. This is sort of frustrating. I'm thinking my only other option is to just configure an s3 input for splunk. I would think I'd be able to pull in more accounts than this.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...