Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Harnessing Splunk’s Federated Search for Amazon S3

NickG
Splunk Employee
Splunk Employee

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated Search for Amazon S3 (FS-S3) helps you do just that. It lets you search and analyze historical or archival data directly in your Amazon S3 buckets without ingesting it into Splunk first. The result? You save on storage costs, shorten time-to-detection, and maintain tighter compliance.

Key Benefits

  • Reduced Storage Costs: Keep data where it lives in cost-effective Amazon S3 and query it on-demand—minimizing data ingestion and lowering overall storage expenses.
  • Improved Time-to-Detection: Access and investigate historical data directly in Amazon S3 without rehydrating or moving it.
  • Enhanced Compliance: Keep data in its original location to maintain compliance and streamline governance, only searching it when needed.

See Federated Search for Amazon S3 in Action

Ready to learn how this transformative capability works? Watch our new video and learn how to integrate Federated Search for Amazon S3 into your existing workflows.

Additional Resources

  • Check out the Federated Search for S3 Tech Brief for an in-depth look at technical features.
  • Explore our webinar recording for a guided setup walkthrough and a live demo.
  • Dive into this blog post to learn how to get started with key compliance use cases.

Get Started Today

Federated Search for Amazon S3 is generally available on the Splunk Cloud Platform and requires a Data Scan Units license for your Splunk Cloud stack. Contact your Splunk sales representative to start using FS-S3 today. 

Get Updates on the Splunk Community!

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...

Splunk AppDynamics Agents Webinar Series

Mark your calendars! On June 24th at 12PM PST, we’re going live with the second session of our Splunk ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...