All Apps and Add-ons

Splunk App for AWS: How to get Application Elastic Load Balancing metrics to show up under Cloudwatch metrics?

rh0dium
Explorer

How do you get Application Elastic Load Balancing (ELB) metrics to show up under Splunk App for AWS Cloudwatch metrics?

0 Karma

stuartidelta01
Path Finder

In the current version (4.4) - open the Splunk Add-On for AWS:

  1. Inputs -> Create New Input -> Cloudwatch
  2. Name=whatever-you-want e.g. AWS ALB
  3. Account=select the account - you have already setup
  4. Assume Role = leave blank or use role if this is your method
  5. AWS Regions = select one or more regions as required
  6. Click on "Edit in Advanced Mode"
  7. Remove all the exising namespaces
  8. Click Add Namespace
  9. Type: AWS/ApplicationELB and hit Enter
  10. The dimensions and metrics should now update to reflect the dimensions of this namespace
  11. You can modify these as required or leave them as is
  12. Click OK
  13. Set your desired destination index
  14. Set your polling interval and period - Cloudwatch updates these metrics every 60 seconds so you could go for 60 and 60 for these to get the finest level of detail
  15. Hit Save

After a few minutes your index should be populated with the metrics.

General Note:

Some of the cloudwatch namespaces appear by default when you select New Input - Cloudwatch (e.g. EC2,
Many more are available when you click on Add namespace and start typing
Some are not there at all and you have to define them yourself

The AWS CloudWatch metrics reference helps:

http://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CW_Support_For_AWS.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...