Getting Data In

cloudwatch logs tagging

okana
Loves-to-Learn Lots

Expert advice needed.

I was able to ingest cloudwatch logs for ecs and lambda with data manager

Now i need to add tags like env= service= custom= to enrich logs

Same was done for metrics with otel collector flags and UF

For logs ingested with DM can i add aws resource tag to cloudwatch loggroup i'm ingesting and expect this tag (key-value pair) to be added to logs

Another possible solution could be to use splunk log driver directly from ecs instead of cloudwatch. Then according to documentation with env flag of splunk log driver I should be able to add some container env to log message

Same question for the lambdas.

But if only cloudwatch loggroup aws resource tags from the loggroup are able to be attached to ingested message.

Any suggestions?

Labels (1)
Tags (1)
0 Karma

marnall
Motivator

Assuming that you are able to edit the inputs.conf file, and that you have a definite value for env, service, and custom for each input stanza, then you could add meta tags to the input stanzas:

_meta = env::<env value> service::<service value> custom::<custom value>

I don't know if this works the same way with OTEL collectors.

0 Karma

okana
Loves-to-Learn Lots

In my case it is data manager or possibly lambda. There is no inputs.conf in both cases. 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...