All Apps and Add-ons

Splunk App for AWS: Why am I not able to see custom metrics created in AWS?

chrismmckenna
New Member

We have some custom EC2 CloudWatch metrics created in our AWS account. I have configured the Splunk App for AWS to collect all EC2 metrics, but I do not see the custom metrics created in AWS.

0 Karma

derick_kotze
New Member

Did anyone ever resolve the issue around onboarding custom metrics via the AWS TA? 

0 Karma

kongusuresh
New Member

I have configured input file to capture the custom logs, but there are metics in Splunk can you please assist
[aws_cloudwatch://test-CWagent_cca2f8c6-b830-41c1-8703-f2f22781a174]
aws_account = ***********
aws_region = ap-southeast-2
metric_dimensions = [{"InstanceId":["."]}]
index = *
****_cwagent
metric_names = ".
"
metric_namespace = CWAgent
period = 600
polling_interval = 3600
sourcetype = aws:cloudwatch
use_metric_format = false
statistics = ["Average","Sum","SampleCount","Maximum","Minimum"]
metric_expiration = 3600
query_window_size = 24

0 Karma

jzhong_splunk
Splunk Employee
Splunk Employee

What's the namespace for your custom metrics? By default the AWS App collections all metrics names under AWS/EC2. If you check the input in the AWS TA, the metrics names are wildcard .*

If you define own metrics namespace, you can use the AWS Add-on configuration to type the namespace and custom metrics name/dimensions. The URL are en-US/app/Splunk_TA_aws/inputs and docs are http://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatch

mvdp
New Member

I am having the same problem. I added the namespace to the input configuration in the AWS Add-on following the documentation, and I can see in the logs that it is finding the metrics, however I am not seeing any events in the add-on for the custom namespace metrics.

The splunk_ta_aws_cloudwatch.log has a line like this in it "Discovered total=6 metrics and dimentions in namespace=, region=xxxx for datainput=xxxx, batchsize=6"

I was initially having configuration issues and not getting the data (the line above would instead say it hadn't found anything for the namespace). According to the "Health Check" in the AWS Add-on I have no errors.

Can you help me figure out why I am still seeing no data for the custom namespace please?

0 Karma

jeremy059
Explorer

Same here on my end. I made sure the custom metrics are named according to the documentation. Tried using some wildcards as well. Still can't see custom metrics.

Sample advanced configuration looks like this:

Namespace:
Somename/Default

Dimension:
hostname

Dimension Value:
[{"hostname":[".*]}]

Metrics:
All

Metric Statistics:
Average

Has anyone able to ingest custom CloudWatch metrics?

Thanks.

Kind regards,
Jeremy

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...