Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Harnessing Splunk’s Federated Search for Amazon S3

NickG
Splunk Employee
Splunk Employee

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated Search for Amazon S3 (FS-S3) helps you do just that. It lets you search and analyze historical or archival data directly in your Amazon S3 buckets without ingesting it into Splunk first. The result? You save on storage costs, shorten time-to-detection, and maintain tighter compliance.

Key Benefits

  • Reduced Storage Costs: Keep data where it lives in cost-effective Amazon S3 and query it on-demand—minimizing data ingestion and lowering overall storage expenses.
  • Improved Time-to-Detection: Access and investigate historical data directly in Amazon S3 without rehydrating or moving it.
  • Enhanced Compliance: Keep data in its original location to maintain compliance and streamline governance, only searching it when needed.

See Federated Search for Amazon S3 in Action

Ready to learn how this transformative capability works? Watch our new video and learn how to integrate Federated Search for Amazon S3 into your existing workflows.

Additional Resources

  • Check out the Federated Search for S3 Tech Brief for an in-depth look at technical features.
  • Explore our webinar recording for a guided setup walkthrough and a live demo.
  • Dive into this blog post to learn how to get started with key compliance use cases.

Get Started Today

Federated Search for Amazon S3 is generally available on the Splunk Cloud Platform and requires a Data Scan Units license for your Splunk Cloud stack. Contact your Splunk sales representative to start using FS-S3 today. 

Contributors
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...