All Apps and Add-ons

Reading log files from Amazon S3

grahampoulter
Path Finder

We're considering Amazon Elastic Beanstalk. The application logs will get rotated to S3 buckets, so I'm asking if there is a Splunk app or other well-supported method to read logs from S3 into Splunk.

Tags (2)
1 Solution

khourihan_splun
Splunk Employee
Splunk Employee

You can try our S3 app here: http://apps.splunk.com/app/1137/

Or you can mount your S3 as a filesystem and have a Universal Forwarder monitor it like a directory. There is a good writeup here: http://www.reedmurphy.net/blog/post/splunking-through-amazon-s3-access-logs

I suggest going the s3cmd route, its a little more feature rich than the Splunk app, but I have used both with success.

View solution in original post

khourihan_splun
Splunk Employee
Splunk Employee

You can try our S3 app here: http://apps.splunk.com/app/1137/

Or you can mount your S3 as a filesystem and have a Universal Forwarder monitor it like a directory. There is a good writeup here: http://www.reedmurphy.net/blog/post/splunking-through-amazon-s3-access-logs

I suggest going the s3cmd route, its a little more feature rich than the Splunk app, but I have used both with success.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...