Getting Data In

Multiple Indexes, single S3 Bucket with SQS

megabit
New Member

Given a Splunk environment with SQS (S3) as the data source, is it possible to "filter" messages at  so that we can separate each file (based on its prefix) to different Splunk indexes?

Put another way, if we have 25 indexes, corresponding to 25 different data types in an S3 bucket, and we want to use S3 and SQS, can we configure Splunk to conditionally index the data based on a path/prefix match pattern applied to each SQS message?

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...