Data is coming from AWS using Splunk add-on for AWS. We are getting that in JSON format. And collecting only operational data. So, in Splunk add-on for AWS, in inputs section, do we use direct cloud watch input OR do we go to custom and select cloudwatch logs in there? we don't have any UF or HF, I'm using Splunk add-on for AWS to get the data in. And getting JSON data. Not sure how all field extractions and all work, do we even need to perform that if we are getting json data??
... View more