Getting Data In

Can Data Manager import Cloudwatch ECS Fargate logs?

nramella
Engager

I'm using current Cloud Splunk:

It appears the older "Splunk Add-on for AWS" can stream in Cloudwatch log-group data through Inputs > Custom Data Type > Cloudwatch Logs. This asks for a comma separated log-groups to feed of of and presumably setups up ingest for them.

Data Manager has a Cloudwatch Logs section,  but it appears to only cover

  • AWS Cloudtrail
  • AWS Security Hub
  • Amazon Guard Duty
  • IAM Access Analyzer
  • IAM Credential support
  • Metadata (EC2, IAM, Network ACLs, EC2 sec groups)

Am I just missing something in Data Manager, does it support ingesting Cloudwatch log-groups?

Should I use "Splunk Add-On for AWS"?

Should forgo both and instead use the splunk log driver with the container tasks as per https://repost.aws/knowledge-center/ecs-task-fargate-splunk-log-driver (posted a year ago)

Thank you!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...