Getting Data In

Delay in Access Logs from S3

patterc
Path Finder

I've enabled Access Logging on an S3 bucket so I can have a record of when files are POSTed to the bucket. In addition to this, I've told the Splunk Add-On for AWS to look for new access log records every 60 seconds in the bucket as well. 

The problem is that I don't see these access logs in Splunk until hours (up to 3 or 4) after the files exist in the log on S3. If this is checking every minute, why am I not getting any results? I don't think it's a timezone issue, because if I am reading the configuration details correctly, it should just check for new records and not worry about timezones. 

patterc_0-1660323006212.png

patterc_1-1660323120431.png

 

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...