Getting Data In

Can Data Manager import Cloudwatch ECS Fargate logs?

nramella
Engager

I'm using current Cloud Splunk:

It appears the older "Splunk Add-on for AWS" can stream in Cloudwatch log-group data through Inputs > Custom Data Type > Cloudwatch Logs. This asks for a comma separated log-groups to feed of of and presumably setups up ingest for them.

Data Manager has a Cloudwatch Logs section,  but it appears to only cover

  • AWS Cloudtrail
  • AWS Security Hub
  • Amazon Guard Duty
  • IAM Access Analyzer
  • IAM Credential support
  • Metadata (EC2, IAM, Network ACLs, EC2 sec groups)

Am I just missing something in Data Manager, does it support ingesting Cloudwatch log-groups?

Should I use "Splunk Add-On for AWS"?

Should forgo both and instead use the splunk log driver with the container tasks as per https://repost.aws/knowledge-center/ecs-task-fargate-splunk-log-driver (posted a year ago)

Thank you!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...