Splunk Enterprise

Splunk index is consuming more voulmes if cloudtrail input is enabled

splunkdemo
New Member

I'm trying to fetch the logs to Splunk from AWS Cloudtrail using Splunk Addon for AWS. When I checked the s3 bucket size it shows only 2GB data. But if I enable the Cloudtrail input in Addon, the Splunk index is consuming over 3 or 4 GB. My configuration is correct in the addon input and I'm only getting the logs in Splunk from the data range that I specified in the addon.

Is this something related to the compression of data in AWS and Splunk are different. Please help to resolve this.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...