Getting Data In

cloudwatch logs tagging

okana
Loves-to-Learn Lots

Expert advice needed.

I was able to ingest cloudwatch logs for ecs and lambda with data manager

Now i need to add tags like env= service= custom= to enrich logs

Same was done for metrics with otel collector flags and UF

For logs ingested with DM can i add aws resource tag to cloudwatch loggroup i'm ingesting and expect this tag (key-value pair) to be added to logs

Another possible solution could be to use splunk log driver directly from ecs instead of cloudwatch. Then according to documentation with env flag of splunk log driver I should be able to add some container env to log message

Same question for the lambdas.

But if only cloudwatch loggroup aws resource tags from the loggroup are able to be attached to ingested message.

Any suggestions?

Labels (1)
Tags (1)
0 Karma

marnall
Motivator

Assuming that you are able to edit the inputs.conf file, and that you have a definite value for env, service, and custom for each input stanza, then you could add meta tags to the input stanzas:

_meta = env::<env value> service::<service value> custom::<custom value>

I don't know if this works the same way with OTEL collectors.

0 Karma

okana
Loves-to-Learn Lots

In my case it is data manager or possibly lambda. There is no inputs.conf in both cases. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...