Getting Data In

Can Data Manager import Cloudwatch ECS Fargate logs?

nramella
Engager

I'm using current Cloud Splunk:

It appears the older "Splunk Add-on for AWS" can stream in Cloudwatch log-group data through Inputs > Custom Data Type > Cloudwatch Logs. This asks for a comma separated log-groups to feed of of and presumably setups up ingest for them.

Data Manager has a Cloudwatch Logs section,  but it appears to only cover

  • AWS Cloudtrail
  • AWS Security Hub
  • Amazon Guard Duty
  • IAM Access Analyzer
  • IAM Credential support
  • Metadata (EC2, IAM, Network ACLs, EC2 sec groups)

Am I just missing something in Data Manager, does it support ingesting Cloudwatch log-groups?

Should I use "Splunk Add-On for AWS"?

Should forgo both and instead use the splunk log driver with the container tasks as per https://repost.aws/knowledge-center/ecs-task-fargate-splunk-log-driver (posted a year ago)

Thank you!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...