Getting Data In

Can Splunk Forward raw logs directly to AWS S3 Yes/No?

jurschel
Loves-to-Learn

Can a splunk forwarder send logs directly to an S3 bucket without any other intervention as well as send to the splunk indexer? I've looked at the articles that might pertain to this question and the only one that is a definitive yes/no response was almost 4 years ago now. Perhaps something has changed in that time? I'm looking for yes the forwarder can do that and here's how or no the forwarder cannot do that. I've looked at this documentation as well https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Forwarddatatothird-partysystemsd
and it doesn't really clear it up because as I'm not sure it would let you put the FQDN of the S3 bucket in there on port 443.

Tags (2)
0 Karma

tiagofbmm
Influencer

What you could do is to use the export scripts in the Python SDK of Splunk to export Splunk data into S3 buckets

0 Karma

jurschel
Loves-to-Learn

Thanks for responding to the question. The issue is I don't want my data stored in splunk format. I want the raw logs written to S3 such that we maintain a copy of all raw logging for other purposes.

0 Karma

skalliger
SplunkTrust
SplunkTrust

No, how should this work? S3 is an object store and thus the UF would need to be able to talk to the API of the object store.

The UF can't do that right now.

Skalli

0 Karma

jurschel
Loves-to-Learn

Thanks. Glad somebody could just say no to the question.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...