- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk App and Add-on for Amazon Web Services: Log search Cloudfront .gz log from S3 files
mounavignesh
New Member
09-07-2020
10:41 AM
I'm not able to search cloud-front logs from S3. There is no results. But I'm able to search ELB logs and Cloud-trail logs from S3.
Below are my input.conf
[splunk_ta_aws_logs://Cloudfront_logs]
aws_account = splunk_DEV
bucket_name = Mybucketname
bucket_region = us-east-1
host_name = s3.amazonaws.com
interval = 1800
log_file_prefix = cdn_logs
log_name_format = ABCDEFGH.%Y-%m-%d-
log_start_date = 2020-01-01
log_type = cloudfront:accesslogs
max_fails = 10000
max_retries = -1
sourcetype = aws:cloudfront:accesslogs
