Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Harnessing Splunk’s Federated Search for Amazon S3

NickG
Splunk Employee
Splunk Employee

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated Search for Amazon S3 (FS-S3) helps you do just that. It lets you search and analyze historical or archival data directly in your Amazon S3 buckets without ingesting it into Splunk first. The result? You save on storage costs, shorten time-to-detection, and maintain tighter compliance.

Key Benefits

  • Reduced Storage Costs: Keep data where it lives in cost-effective Amazon S3 and query it on-demand—minimizing data ingestion and lowering overall storage expenses.
  • Improved Time-to-Detection: Access and investigate historical data directly in Amazon S3 without rehydrating or moving it.
  • Enhanced Compliance: Keep data in its original location to maintain compliance and streamline governance, only searching it when needed.

See Federated Search for Amazon S3 in Action

Ready to learn how this transformative capability works? Watch our new video and learn how to integrate Federated Search for Amazon S3 into your existing workflows.

Additional Resources

  • Check out the Federated Search for S3 Tech Brief for an in-depth look at technical features.
  • Explore our webinar recording for a guided setup walkthrough and a live demo.
  • Dive into this blog post to learn how to get started with key compliance use cases.

Get Started Today

Federated Search for Amazon S3 is generally available on the Splunk Cloud Platform and requires a Data Scan Units license for your Splunk Cloud stack. Contact your Splunk sales representative to start using FS-S3 today. 

Contributors
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...