All Apps and Add-ons

Why is the Splunk Add-on for Amazon Web Services not pulling all Cloudwatch logs?

nickpayze
Explorer

I made a total of 36 inputs, 12 log groups from various regions. For some reason I do not receive data from the last two log groups in alphabetical order. So I receive logs just fine for all logs starting with an "A" and on, but do not get anything from my last two logs starting with a "P" since they are the last logs in the list. If I change the name of one of the last few inputs by inserting an "A" at the beginning of the name, I receive events from that log group again, but then the next log group gets pushed down the list and I stop receiving events from that one instead. Is this a bug with the AWS add-on?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Can you please file a support ticket so we can diagnose this behavior?

0 Karma

nickpayze
Explorer

We have not purchased Splunk as of yet. Inputting a ticket will definitely be one of the first things we do if a future update doesn't fix this by then 🙂

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...