Getting Data In

How to index data from AWS into Splunk?

duddukurimd
New Member

We want to move files from Amazon s3 to Splunk server (ex: /opt/splunk/logs ) continuously and display those details in Splunk dynamically.

How can we move files from Amazon s3 bucket to Splunk? any suggestion on we can handle this?

0 Karma

FrankVl
Ultra Champion

I would suggest taking a look at the Splunk Add-on for AWS, which supports collecting data from S3: https://splunkbase.splunk.com/app/1876/

Alternatively you could look at creating a scripted input that uses the aws cli library to pull data from s3, store it in /opt/splunk/logs and then process it from there.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...