All Apps and Add-ons

sourcetype tags for aws:s3:accesslogs

Splunk_rocks
Path Finder

Hello splunkers,

Just trying to add appropriate tags and map to data model in ES for AWS log sourcetype -aws:s3:accesslogs
Any one had any luck what data model fits fr this log sources and what types of tag i can add it.

0 Karma

woodcock
Esteemed Legend

Access logs should always go into the Authentication datamodel which uses the authentication tag:
https://docs.splunk.com/Documentation/CIM/latest/User/Authentication

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...