All Apps and Add-ons

How to ingest log files stored in s3 to splunk cloud using aws lambda?

jruizv
Engager

Hey there, I am currently trying to ingest to Splunk cloud log files that, after some processing, are being stored on s3.

I can basically identify 2 strategies here:

  1. Each time a file comes in, a lambda is triggered that parses line by line and forwards each one of those to the HEC. I could loosely follow this guide for that https://www.splunk.com/blog/2017/02/03/how-to-easily-stream-aws-cloudwatch-logs-to-splunk.html (the lambda blueprint part)
  2. Forward entire files to Splunk cloud, but I have no idea how to achieve that without setting up an ec2 instance

How can I achieve number 2? as to my understanding, would be the best course of action.

Best Regards,

Tags (2)
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...