- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are going to integrate WAF logs from AWS SQS
what is the best way to do it ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @rayar,
are you working on Splunk Cloud or Splunk Enterprise?
if you're working on Splunk Cloud you have two ways:
- Data Manager (https://docs.splunk.com/Documentation/SplunkCloud/8.2.2202/Admin/IntroGDI)
- TA_AWS (https://splunkbase.splunk.com/app/1876/)
in the above links you have detailed step by step instructions.
If instead you're working on Splunk Enterprise, you can use only TA_AWS.
Anyway, I configured them few days ago and I can say that it's very easy!
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
we are working on Splunk Enterprise , do you mean ?
https://splunkbase.splunk.com/app/1274/
what source type your used ?
also I see that they have announced an End of Life plan for Splunk App for AWS
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @rayar,
you have to use TA_AWS that isn't in EoL to ingest data.
This app gives you all the ingesting and parsing data structures, you have only to follow the instructions at the documentation link I shared and you haven't any problem about sourcetype, parsing etc...
About App for AWS, yes it's in EoL but there is a new App "Splunk App for AWs Security Dashboard" (https://splunkbase.splunk.com/app/6311/) that replace the old one.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @rayar,
are you working on Splunk Cloud or Splunk Enterprise?
if you're working on Splunk Cloud you have two ways:
- Data Manager (https://docs.splunk.com/Documentation/SplunkCloud/8.2.2202/Admin/IntroGDI)
- TA_AWS (https://splunkbase.splunk.com/app/1876/)
in the above links you have detailed step by step instructions.
If instead you're working on Splunk Enterprise, you can use only TA_AWS.
Anyway, I configured them few days ago and I can say that it's very easy!
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @rayar,
good for you, see next time.
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉
