All Apps and Add-ons

Why is the Splunk Add-on for Amazon Web Services not pulling all Cloudwatch logs?

nickpayze
Explorer

I made a total of 36 inputs, 12 log groups from various regions. For some reason I do not receive data from the last two log groups in alphabetical order. So I receive logs just fine for all logs starting with an "A" and on, but do not get anything from my last two logs starting with a "P" since they are the last logs in the list. If I change the name of one of the last few inputs by inserting an "A" at the beginning of the name, I receive events from that log group again, but then the next log group gets pushed down the list and I stop receiving events from that one instead. Is this a bug with the AWS add-on?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Can you please file a support ticket so we can diagnose this behavior?

0 Karma

nickpayze
Explorer

We have not purchased Splunk as of yet. Inputting a ticket will definitely be one of the first things we do if a future update doesn't fix this by then 🙂

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...