Getting Data In

Forwarding data to S3 buckets before or after or while indexing into Splunk?

dm1
Contributor

I have a requirement to forward Okta logs to S3 buckets, in addition to ingesting into Splunk.

So I see there might two ways we could forward logs to S3 buckets, 

  1. one being, during input phase, where data can be cloned and forwarded to S3 bucket ?
    1. In the outputs.conf, there is the below parameter which seems like an option that can fulfil above reqmt, however, its still under development.

 

remote_queue.sqs.large_message_store.endpoint = <URL>
* Currently not supported. This setting is related to a feature that is
  still under development.Or after indexing logs into SplunkHowever, I am unsure, whether for both options, there is a clearly documented reliable process to achieve the outcome.Can please advise on this ?

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...