All Apps and Add-ons

TA for AWS: Difference between CloudTrail input and SQS-based-S3 input for CloudTrail

benjaminruland
Explorer

Hi community,

I am trying to get my head around the best way to import CloudTrail data from AWS to Splunk.

What I don't understand right now is the difference between these two ways to get CloudTrail data into Splunk when using the Add-On for AWS.

Both inputs use the same mechanism: CloudTrail data is dumped to an S3 bucket, notifications are sent to SNS and forwarded to SQS, Splunk reads from SQS and fetches the data from S3.

Can somebody give me a hint, how these two ways differ and which way would be recommended?

Thanks!

Labels (1)

sonalipatil
Engager

Hello, 

We are also trying to find out the same. Were you able to figure out the difference or get any response from Splunk.

0 Karma

benjaminruland
Explorer

While I have not found out how the "Cloud Trail input" variant differs from the SQS-based-S3, I tested the SQS-based-S3 variant and it works really well. This variant is also the recommended one as indicated in the Add-On's UI.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...