All Apps and Add-ons

Splunk App for AWS: Why am I not able to see custom metrics created in AWS?

chrismmckenna
New Member

We have some custom EC2 CloudWatch metrics created in our AWS account. I have configured the Splunk App for AWS to collect all EC2 metrics, but I do not see the custom metrics created in AWS.

0 Karma

derick_kotze
New Member

Did anyone ever resolve the issue around onboarding custom metrics via the AWS TA? 

0 Karma

kongusuresh
New Member

I have configured input file to capture the custom logs, but there are metics in Splunk can you please assist
[aws_cloudwatch://test-CWagent_cca2f8c6-b830-41c1-8703-f2f22781a174]
aws_account = ***********
aws_region = ap-southeast-2
metric_dimensions = [{"InstanceId":["."]}]
index = *
****_cwagent
metric_names = ".
"
metric_namespace = CWAgent
period = 600
polling_interval = 3600
sourcetype = aws:cloudwatch
use_metric_format = false
statistics = ["Average","Sum","SampleCount","Maximum","Minimum"]
metric_expiration = 3600
query_window_size = 24

0 Karma

jzhong_splunk
Splunk Employee
Splunk Employee

What's the namespace for your custom metrics? By default the AWS App collections all metrics names under AWS/EC2. If you check the input in the AWS TA, the metrics names are wildcard .*

If you define own metrics namespace, you can use the AWS Add-on configuration to type the namespace and custom metrics name/dimensions. The URL are en-US/app/Splunk_TA_aws/inputs and docs are http://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatch

mvdp
New Member

I am having the same problem. I added the namespace to the input configuration in the AWS Add-on following the documentation, and I can see in the logs that it is finding the metrics, however I am not seeing any events in the add-on for the custom namespace metrics.

The splunk_ta_aws_cloudwatch.log has a line like this in it "Discovered total=6 metrics and dimentions in namespace=, region=xxxx for datainput=xxxx, batchsize=6"

I was initially having configuration issues and not getting the data (the line above would instead say it hadn't found anything for the namespace). According to the "Health Check" in the AWS Add-on I have no errors.

Can you help me figure out why I am still seeing no data for the custom namespace please?

0 Karma

jeremy059
Explorer

Same here on my end. I made sure the custom metrics are named according to the documentation. Tried using some wildcards as well. Still can't see custom metrics.

Sample advanced configuration looks like this:

Namespace:
Somename/Default

Dimension:
hostname

Dimension Value:
[{"hostname":[".*]}]

Metrics:
All

Metric Statistics:
Average

Has anyone able to ingest custom CloudWatch metrics?

Thanks.

Kind regards,
Jeremy

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...