Getting Data In

Can Splunk Forward raw logs directly to AWS S3 Yes/No?

jurschel
Loves-to-Learn

Can a splunk forwarder send logs directly to an S3 bucket without any other intervention as well as send to the splunk indexer? I've looked at the articles that might pertain to this question and the only one that is a definitive yes/no response was almost 4 years ago now. Perhaps something has changed in that time? I'm looking for yes the forwarder can do that and here's how or no the forwarder cannot do that. I've looked at this documentation as well https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Forwarddatatothird-partysystemsd
and it doesn't really clear it up because as I'm not sure it would let you put the FQDN of the S3 bucket in there on port 443.

Tags (2)
0 Karma

tiagofbmm
Influencer

What you could do is to use the export scripts in the Python SDK of Splunk to export Splunk data into S3 buckets

0 Karma

jurschel
Loves-to-Learn

Thanks for responding to the question. The issue is I don't want my data stored in splunk format. I want the raw logs written to S3 such that we maintain a copy of all raw logging for other purposes.

0 Karma

skalliger
Motivator

No, how should this work? S3 is an object store and thus the UF would need to be able to talk to the API of the object store.

The UF can't do that right now.

Skalli

0 Karma

jurschel
Loves-to-Learn

Thanks. Glad somebody could just say no to the question.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...