Archive
Highlighted

How to input for s3 buckets compressed file without .gz extension?

Explorer

How to ingest files in S3 buckets that are compressed but do not have .gz extension:
ie: s3://Blah-main/2018/04/20/16/FlowLogsLogsFirehose-us-east-1-DeliveryStream-1THLU7DASFP74-6-2018-04-20-16-10-40-68617538

Highlighted

Re: How to input for s3 buckets compressed file without .gz extension?

Champion
0 Karma
Highlighted

Re: How to input for s3 buckets compressed file without .gz extension?

Explorer

Already using a Splunk App for AWS.

0 Karma
Highlighted

Re: How to input for s3 buckets compressed file without .gz extension?

Communicator

Did you ever come to a solution on this?

I'm also trying to read in an S3 bucket that contains VPC Flow logs. The Splunk App for AWS doesn't seem to realize that they're GZipped data, and it loads in a bunch of garbage text into Splunk instead.

Highlighted

Re: How to input for s3 buckets compressed file without .gz extension?

Contributor

Did you find any solution for this (VPC Flow logs)?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.