All Apps and Add-ons

CloudWatch RDS Logs to Splunk

rducic
New Member

I am using Splunk App for AWS couple of Questions :

In the guide https://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatchLogs it says Splunk strongly recommends against using the CloudWatch Logs inputs to collect VPC Flow Logs data (source type: aws:cloudwatchlogs:vpcflow) since the input type will be deprecated in upcoming releases. Does this relate to RDS as well or is RDS Safe?

Log group A comma-separated list of log group names. Is there a size limit to this filed.
Also is there an API call that updates this value when a new instance is created.

Splunk takes a configuration as $SPLUNK_HOME/etc/apps/Splunk_TA_aws/local/aws_cloudwatch_logs_tasks.conf c*an this file be updated automatically* via a process that would read the list of instances and write it here.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...