Getting Data In

Can Data Manager import Cloudwatch ECS Fargate logs?

nramella
Engager

I'm using current Cloud Splunk:

It appears the older "Splunk Add-on for AWS" can stream in Cloudwatch log-group data through Inputs > Custom Data Type > Cloudwatch Logs. This asks for a comma separated log-groups to feed of of and presumably setups up ingest for them.

Data Manager has a Cloudwatch Logs section,  but it appears to only cover

  • AWS Cloudtrail
  • AWS Security Hub
  • Amazon Guard Duty
  • IAM Access Analyzer
  • IAM Credential support
  • Metadata (EC2, IAM, Network ACLs, EC2 sec groups)

Am I just missing something in Data Manager, does it support ingesting Cloudwatch log-groups?

Should I use "Splunk Add-On for AWS"?

Should forgo both and instead use the splunk log driver with the container tasks as per https://repost.aws/knowledge-center/ecs-task-fargate-splunk-log-driver (posted a year ago)

Thank you!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...