I'm very new to AWS and am setting this up for the first time. I have a "CloudWatch" input for my metrics and a "CloudWatch Logs" input for my logs. The metrics feed works fine. The only problem is that the data that is stored in Splunk from the CloudWatch Logs feed is only the last message in each log stream.
Since I'm getting data, I know most of my settings are correct but something isn't right. For reference, I'm using 60 second interval.
Ideas?
Are the log coming from lambda? could be this issue: https://answers.splunk.com/answers/671220/lambda-cloudwatch-logs-often-missing-due-to-edge-c.html?mi...
If these logs are coming from lambda functions, it won't work. I litreally just made a post about it. https://answers.splunk.com/answers/671220/lambda-cloudwatch-logs-often-missing-due-to-edge-c.html