Splunk Cloud Platform

Splunk Cloud DDSS - AWS S3- Is there a way to change .zst to .gzip?

Ansab
Engager

I am testing Splunk Cloud DDSS to AWS S3 buckets currently. I see logs in my S3 bucket once an index gets rolled over to S3 after its "Searchable Retention" period ends. The question I have is the logs that I see in S3 buckets are compressed using ".zst". Is this a configuration from Splunk or AWS - is there a way to change it to "gzip". Can we not have logs in its default extension and gzip it accordingly.

 

My next step is to test the restore process and it requires a standalone Splunk Enterprise instance. How should I go about that, one indexer and one search head, assuming it will be for one index only?

 

Thank you

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...