Getting Data In

Can Splunk act as a bridge for receiving logs from Meraki and forward it to a s3 bucket?

Sanazinteg
New Member

Hi all,
I need to send our Meraki logs somehow to Splunk and from Splunk to a S3 bucket, but i don't know is this even possible or not? would you please help?

0 Karma

coltwanger
Contributor

I think somesoni2 has a better option with a syslog-ng relay, but you can use the built in syslog routing queue to send data from the Meraki host from Splunk out to S3; look into the _SYSLOG_ROUTING value for DEST_KEY in transforms. Then configure an outputs.conf for your S3 host.

http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Forwarding/Routeandfilterdatad

0 Karma

somesoni2
Revered Legend

There may be workaround, but if you're not going to use data in Splunk after indexing it, why even involve Splunk? Amazon S3 has several CLI tools (http://aws.amazon.com/cli/) which you can use to send data/files to S3 storage.

0 Karma

Sanazinteg
New Member

I want to use slunk as a bridge since I did not find a way that can send the syslog from Meraki directly to S3 bucket.
thanks for quick response.

0 Karma

somesoni2
Revered Legend

I believe it would be better to just setup a syslog-ng on a server to write Meraki logs to file and use S3 CLI tools to upload those files to s3 buckets. This way you can keep the files in exact same format they are received from Meraki.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...