Getting Data In

Splunkcloud - Specify a different sourcetype for Generic S3 input ?

robot2051
New Member

Hello,

We have iis log being stored in a S3 bucket in CSV format. My understanding is sourcetype for CSV will help parsing these events and indexing them as they come in. I would like to use our aws-add-on which includes a generic s3 input to pick up these logs and parse it with either my custom sourcetype or iis sourcetype...

First of all, Is this possible?

I have tried to create this via Splunk add-on for aws -> Input -> Create New Input -> Custom Data Type -> Generic S3 . the sourcetype drop down only has aws specific sourcetype, I could type any sourcetype name and add the input, however when i searched for these events, the events are not parsed and displayed as raw only.

I have also tried using IIS Add-on which come with a sourcetype for iis logs but that didnt work.

Please let me know if you have done it before and got it to work.

Kind regards,
Sam

Tags (1)
0 Karma

robot2051
New Member

Note: Because we are using splunkcloud , unfortunately we can't edit the actual config files as it is not managed by us 😞 Please let me know if there is a documentation or if you know how to achieve this in the UI, that would be great.

Cheers

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...