Send CloudWatch logs to Splunk (2024)

By using AWS re:Post, you agree to the

AWS re:Post

Terms of Use

re:Post

Hi, architectural question here.Goal is to move logs from cloudwatch logs to an on premises Splunk, reliably.

I see different options, with trade-off:

  1. add a lambda subscription filter to the log group and leverage a lambda Splunk blueprint function which is able to push logs. Simple, but risk of throttling if huge amount of logs is sent
  2. Combination of EventBridge scheduler + lambda to move data to s3, and then via fan-out pattern (sns,SQS) to the Splunk lambda logging function. This is more reliable but getting complex and not a big fun of schedules.
  3. Same as above, but using kinesis to move data to s3, and then fanning out to Splunk lambda as before. Also a constraint here is that kinesis may not usable for certain reason.
  4. Cloudwatch subscription filter with a lambda that push data to SNS. Topic is consumed either directly via Splunk lambda, or via SQS which then the Splunk lambda listen too. Risk about throttling and slightly complex architecture.
  5. Need to check feasibility, but was looking for an EventBridge tule, which may listen to log groups and move logs to SNS, and then to Splunk, but haven’t confirmed this yet.

Any other alternatives? Thanks

Topics

Application IntegrationComputeServerless

Tags

Amazon Simple Notification Service (SNS)AWS LambdaAmazon CloudWatch LogsAmazon EventBridge

Language

English

Send CloudWatch logs to Splunk (2)

EXPERT

Antonio_Lagrotterialg...

asked a year ago4516 viewslg...

4 Answers

  • Newest
  • Most votes
  • Most comments

1

Is this to batch move or stream real time as you mention move but then with subscription filters I believe they will only monitor for new events from that point of configuration and not historical events? (Need to confirm)

You could export logs directly to S3 from the console and then import from there. When I have done this in the past, I believe I could only export log groups 1 or 2 at a time.

  • Antonio_Lagrotteria EXPERT

    a year ago

    Main objective here is reliability and no lost logs, so real time or batch not a constraint. As mentioned I m not a big fun of export solution and I know there are limitations with that

  • Gary Mclean EXPERT

    a year ago

    Makes perfect sense! Ta

1

Send CloudWatch logs to Kinesis Firehose https://repost.aws/knowledge-center/cloudwatch-logs-stream-to-kinesis

Kinesis Firehose streams can be sent directly to Splunk for ingestion https://aws.amazon.com/kinesis/data-firehose/splunk/ https://docs.splunk.com/Documentation/AddOns/released/Firehose/ConfigureFirehose

Send CloudWatch logs to Splunk (4)

EXPERT

Steve_Mlg...

answered a year agolg...

Send CloudWatch logs to Splunk (5)

EXPERT

Antonio_Lagrotterialg...

reviewed 5 months agolg...

  • Antonio_Lagrotteria EXPERT

    a year ago

    As mentioned, kinesis may not be used for certain reasons.

  • Steve_M EXPERT

    a year ago

    OK fair enough, if Kinesis Firehose is considered as being part of the Kinesis product then it's out.

    I was reading it too literally and considering them as separate products. And data can be sent from Cloudwatch to Firehose without ever having to touch a Kinesis stream.

1

Why not try Splunk Addon for AWS as outlined here - https://docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatchLogs

Send CloudWatch logs to Splunk (6)

Sydlg...

answered a year agolg...

I would recommend considering using Amazon Kinesis Data Firehose to reliably deliver logs from CloudWatch Logs to Splunk.

Some key advantages of this approach:

  • Kinesis Data Firehose can automatically deliver log data from CloudWatch Logs to Splunk with minimal code required. It handles log aggregation, compression and transport securely at a large scale.
  • Firehose delivers log data reliably to Splunk with options for data transformation along the way if needed. It can also handle high volumes of log data from CloudWatch Logs.
  • This avoids the need to build out and manage your own log delivery infrastructure using Lambda, SNS/SQS etc. which comes with additional operational overhead.
  • Splunk has documentation on how to configure Firehose for log delivery directly to Splunk for ingestion.

To get started, you can create a Firehose delivery stream that sources data from a CloudWatch Logs group and delivers to your Splunk endpoint. The AWS documentation provides steps to set this up. Let me know if you have any other questions!

Send CloudWatch logs to Splunk (7)

EXPERT

Giovanni Laurialg...

answered 5 months agolg...

Relevant content

  • CloudWatch logs are not reaching Splunk for the new lambda with AWS Firehose/Lambda integration

    rePost-User-0342927lg...

    asked 2 years agolg...

  • debugging using cloudwatch logs from different

    G V Navinlg...

    asked 2 years agolg...

  • Splunk vs Amazon OpenSearch vs CloudWatch

    Mounirlg...

    asked 9 months agolg...

  • How can we filter logstreams while adding a Splunk Subscription on aws batch logs using Cloud Formation Template?

    Anupriyalg...

    asked 7 months agolg...

  • How do I push VPC flow logs to Splunk using Amazon Kinesis Firehose?

    Send CloudWatch logs to Splunk (8)

    AWS OFFICIALUpdated a year ago

  • How do I use a Splunk log driver with an Amazon ECS task on Fargate?

    Send CloudWatch logs to Splunk (9)

    AWS OFFICIALUpdated 4 months ago

  • How do I determine throttling in my CloudWatch logs?

    Send CloudWatch logs to Splunk (10)

    AWS OFFICIALUpdated 2 years ago

  • How do I resolve throttling errors in my CloudWatch logs?

    Send CloudWatch logs to Splunk (11)

    AWS OFFICIALUpdated 6 months ago

  • How can I send AWS WAF log to both CloudWatch logs and S3?

    Send CloudWatch logs to Splunk (12)Send CloudWatch logs to Splunk (13)

    EXPERT

    Lei Peilg...

    published 3 months agolg...

  • How to view consolidated log from multiple log streams generated from an AWS Mainframe Modernization application?

    Send CloudWatch logs to Splunk (14)Send CloudWatch logs to Splunk (15)

    EXPERT

    Souma Suvra Ghoshlg...

    published 8 months agolg...

Send CloudWatch logs to Splunk (2024)
Top Articles
Starbucks cheese danish recipe
Crispy Baked Sweet Potato Fries Recipe - Kristine's Kitchen
Bad Moms 123Movies
Extranet Landing Page Delta
Bannerlord Campaign Or Sandbox
Tiffany's Breakfast Portage
Use Caution: Herds of wild horses escaping Davis Fire spotted evacuating up Geiger Grade
Retail Jobs For Teens Near Me
Stellaris Mid Game
Rooms for rent in Pompano Beach, Broward County, FL
John W Creasy Died December 16 2003
Oriellys Bad Axe
I've spent £23,000 to stay in the UK but it could all be for nothing
Fisher-Cheney Funeral Home Obituaries
Okay Backhouse Mike Lyrics
Alishbasof
Robert Rushing Net Worth, Daughter, Age, and Wikipedia
Drug Stores Open 24Hrs Near Me
Wdl Nursing Abbreviation
‘There’s no Planet B’: UNLV first Nevada university to launch climate change plan
Kickflip Seeds
Jen Chapin Gossip Bakery
Haktuts.in Coin Master 50 Spin Link
Best Restaurants In Lynnwood
Urbfsdreamgirl
Best Birthday Dinner Los Angeles
Courtney Lynn Playboy
Pearl City Hall Pearl Ms
Aka.ms/Compliancelock
Dollar General Cbl Answers Shrink Awareness
La Times Jumble Answer Today
Banning Beaumont Patch
Katie Sigmond - Net Worth 2022, Age, Height, Bio, Family, Career
A-Z List of Common Medical Abbreviations, Acronyms & Definitions
Aspect of the Dragons
Sunset Time Yesterday
Claudia Capertoni Only Fans
Gunblood Unblocked 66
Craigslist/Lakeland
Inland Empire Heavy Equipment For Sale By Owner
Famous Church Sermons
Nail salons near me in West Hartford. Find a nail shop on Booksy!
Busted Newspaper Mcpherson Kansas
Heatinghelp The Wall
Unity Webgl Car Tag
Hotels Near William Woollett Jr Aquatics Center
Braveheart Parents Guide
Craigslist Cars By Owner
Great Clips Fremont Ohio
O'reilly's Covington Tennessee
I Only Have Eyes for You by The Flamingos Lyrics Meaning - A Gaze Into Love's Timeless Power - Song Meanings and Facts
Priority Pass: How to Invite as Many Guests as Possible to Airport Lounges?
Latest Posts
Article information

Author: Errol Quitzon

Last Updated:

Views: 5467

Rating: 4.9 / 5 (79 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.