Getting Data In

cloudwatch logs tagging

okana
Loves-to-Learn Lots

Expert advice needed.

I was able to ingest cloudwatch logs for ecs and lambda with data manager

Now i need to add tags like env= service= custom= to enrich logs

Same was done for metrics with otel collector flags and UF

For logs ingested with DM can i add aws resource tag to cloudwatch loggroup i'm ingesting and expect this tag (key-value pair) to be added to logs

Another possible solution could be to use splunk log driver directly from ecs instead of cloudwatch. Then according to documentation with env flag of splunk log driver I should be able to add some container env to log message

Same question for the lambdas.

But if only cloudwatch loggroup aws resource tags from the loggroup are able to be attached to ingested message.

Any suggestions?

Labels (1)
Tags (1)
0 Karma

marnall
Motivator

Assuming that you are able to edit the inputs.conf file, and that you have a definite value for env, service, and custom for each input stanza, then you could add meta tags to the input stanzas:

_meta = env::<env value> service::<service value> custom::<custom value>

I don't know if this works the same way with OTEL collectors.

0 Karma

okana
Loves-to-Learn Lots

In my case it is data manager or possibly lambda. There is no inputs.conf in both cases. 

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...