Splunk Cloud Platform

Splunk Cloud DDSS - AWS S3- Is there a way to change .zst to .gzip?

Ansab
Engager

I am testing Splunk Cloud DDSS to AWS S3 buckets currently. I see logs in my S3 bucket once an index gets rolled over to S3 after its "Searchable Retention" period ends. The question I have is the logs that I see in S3 buckets are compressed using ".zst". Is this a configuration from Splunk or AWS - is there a way to change it to "gzip". Can we not have logs in its default extension and gzip it accordingly.

 

My next step is to test the restore process and it requires a standalone Splunk Enterprise instance. How should I go about that, one indexer and one search head, assuming it will be for one index only?

 

Thank you

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...