All Apps and Add-ons

CloudWatch logs via HEC on Splunk Light Cloud?

trauts2
New Member

This article shows how I was hoping to ingest our CloudWatch logs https://www.splunk.com/blog/2017/02/03/how-to-easily-stream-aws-cloudwatch-logs-to-splunk.html

But after installing the AWS into Splunk Light Cloud, the instructions don't match up. Is there a more recent and comprehensible instruction for configuring Splunk Light to consume logs in CloudWatch? I was surprised at how difficult this is, which makes me think I haven't found the right docs yet.

Thanks!

0 Karma
1 Solution

gneumann_splunk
Splunk Employee
Splunk Employee

Here are some resources to help you with your configuration:

Splunk Light documentation to configure App and Add-on for AWS in Splunk Light cloud service.
- Do your AWS planning, and configure services and permissions in AWS
- Configure Splunk Light, paying particular attention to Step 3 for setting up Splunk Light:
http://docs.splunk.com/Documentation/SplunkLight/7.0.1/Installation/GettingstartedSplunkAppforAWS

YouTube Videos you can watch that provide great information about configuring AWS services and permissions:
- Splunk App for AWS configuration & AWS prep walkthrough:
https://www.youtube.com/watch?v=U_esFvx6GHY
- Click Show More to see CloudWatch specific info:
https://www.youtube.com/watch?v=U_esFvx6GHY&feature=youtu.be&t=1673

Hoping this info gets you up and running.

View solution in original post

0 Karma

gneumann_splunk
Splunk Employee
Splunk Employee

Here are some resources to help you with your configuration:

Splunk Light documentation to configure App and Add-on for AWS in Splunk Light cloud service.
- Do your AWS planning, and configure services and permissions in AWS
- Configure Splunk Light, paying particular attention to Step 3 for setting up Splunk Light:
http://docs.splunk.com/Documentation/SplunkLight/7.0.1/Installation/GettingstartedSplunkAppforAWS

YouTube Videos you can watch that provide great information about configuring AWS services and permissions:
- Splunk App for AWS configuration & AWS prep walkthrough:
https://www.youtube.com/watch?v=U_esFvx6GHY
- Click Show More to see CloudWatch specific info:
https://www.youtube.com/watch?v=U_esFvx6GHY&feature=youtu.be&t=1673

Hoping this info gets you up and running.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...