All Apps and Add-ons

Splunk App for AWS: Why am I not able to see custom metrics created in AWS?

New Member

We have some custom EC2 CloudWatch metrics created in our AWS account. I have configured the Splunk App for AWS to collect all EC2 metrics, but I do not see the custom metrics created in AWS.

0 Karma

New Member

I have configured input file to capture the custom logs, but there are metics in Splunk can you please assist
[aws_cloudwatch://test-CWagent_cca2f8c6-b830-41c1-8703-f2f22781a174]
aws_account = ***********
aws_region = ap-southeast-2
metric_dimensions = [{"InstanceId":["."]}]
index = *
****_cwagent
metric_names = ".
"
metric_namespace = CWAgent
period = 600
polling_interval = 3600
sourcetype = aws:cloudwatch
use_metric_format = false
statistics = ["Average","Sum","SampleCount","Maximum","Minimum"]
metric_expiration = 3600
query_window_size = 24

0 Karma

Splunk Employee
Splunk Employee

What's the namespace for your custom metrics? By default the AWS App collections all metrics names under AWS/EC2. If you check the input in the AWS TA, the metrics names are wildcard .*

If you define own metrics namespace, you can use the AWS Add-on configuration to type the namespace and custom metrics name/dimensions. The URL are en-US/app/Splunk_TA_aws/inputs and docs are http://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatch

New Member

I am having the same problem. I added the namespace to the input configuration in the AWS Add-on following the documentation, and I can see in the logs that it is finding the metrics, however I am not seeing any events in the add-on for the custom namespace metrics.

The splunk_ta_aws_cloudwatch.log has a line like this in it "Discovered total=6 metrics and dimentions in namespace=, region=xxxx for datainput=xxxx, batchsize=6"

I was initially having configuration issues and not getting the data (the line above would instead say it hadn't found anything for the namespace). According to the "Health Check" in the AWS Add-on I have no errors.

Can you help me figure out why I am still seeing no data for the custom namespace please?

0 Karma

Explorer

Same here on my end. I made sure the custom metrics are named according to the documentation. Tried using some wildcards as well. Still can't see custom metrics.

Sample advanced configuration looks like this:

Namespace:
Somename/Default

Dimension:
hostname

Dimension Value:
[{"hostname":[".*]}]

Metrics:
All

Metric Statistics:
Average

Has anyone able to ingest custom CloudWatch metrics?

Thanks.

Kind regards,
Jeremy

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!