Splunk Enterprise

AWS cloudwatch logs to splunk on prem

Narendra_Rao
Loves-to-Learn Lots

We have logs already in CloudWatch. What is the best way to take the logs from cloudwatch to splunk on prem.
We have a vpn established too between them . So based on this any Add ons or other viable solution other than Add ons.
If yes : Any details /steps etc.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Narendra_Rao 

There are a number of different ways to get AWS Cloudwatch logs out of AWS into your on-prem environment, ultimately I think this will depend on how where your VPN terminates and which AWS services can connect to it.

I tend to go with using AWS Firehose which sends to your Splunk HEC endpoint - Check out https://aws.amazon.com/blogs/big-data/deliver-decompressed-amazon-cloudwatch-logs-to-amazon-s3-and-s... for more information on this.

Alternatively you can send using AWS Lambda instead of Firehose, this also sends to HEC - Check out https://www.splunk.com/en_us/blog/platform/stream-amazon-cloudwatch-logs-to-splunk-using-aws-lambda.... for more info on this.

There may be others, but ultimately it depends on your connection - do either of these look suitable for your environment? Let me know if you need more info?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...