Getting Data In

Can Splunk Forward raw logs directly to AWS S3 Yes/No?

jurschel
Loves-to-Learn

Can a splunk forwarder send logs directly to an S3 bucket without any other intervention as well as send to the splunk indexer? I've looked at the articles that might pertain to this question and the only one that is a definitive yes/no response was almost 4 years ago now. Perhaps something has changed in that time? I'm looking for yes the forwarder can do that and here's how or no the forwarder cannot do that. I've looked at this documentation as well https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Forwarddatatothird-partysystemsd
and it doesn't really clear it up because as I'm not sure it would let you put the FQDN of the S3 bucket in there on port 443.

Tags (2)
0 Karma

tiagofbmm
Influencer

What you could do is to use the export scripts in the Python SDK of Splunk to export Splunk data into S3 buckets

0 Karma

jurschel
Loves-to-Learn

Thanks for responding to the question. The issue is I don't want my data stored in splunk format. I want the raw logs written to S3 such that we maintain a copy of all raw logging for other purposes.

0 Karma

skalliger
Motivator

No, how should this work? S3 is an object store and thus the UF would need to be able to talk to the API of the object store.

The UF can't do that right now.

Skalli

0 Karma

jurschel
Loves-to-Learn

Thanks. Glad somebody could just say no to the question.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...