Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (2024)

The latest feature release of Splunk Data Manager – Custom Logs – empowers users with access to a wide spectrum of AWS service logs, ensuring comprehensive coverage among an ever-evolving cloud computing landscape.

Before you dive into the detailed blog content, take a moment to check out our video explaining Custom Logs. This quick introduction is designed to give you a clear overview of how Custom Logs can improve your log management experience.

This article is divided into two sections: first, we explore the essence of 'Custom Logs', and then we provide a detailed, user-centric guide for integrating custom logs into Splunk using EC2 and Lambda logs.

What Are Custom Logs?

Encountered challenges in ingesting diverse logs from your AWS services? Custom Logs in Splunk Data Manager are here to change that. This feature broadens your log ingestion capabilities, allowing for seamless integration of a wider array of AWS service logs into Splunk. It's all about adaptability and user-centricity.

With Custom Logs, you're no longer limited to standard log types. From intricate AWS service logs to unique application logs, you have the flexibility to bring everything into Splunk for comprehensive analysis. This enhancement is more than a feature; it's your solution to the increasing complexity of cloud-based log data, tailored to offer deeper insights and a clearer view of your entire AWS landscape.

The Rationale Behind Custom Logs

Splunk Cloud Platform customers engage with a diverse range of AWS services, each producing its own set of logs stored in CloudWatch Logs groups. While Data Manager efficiently supports a subset of these services, a broad spectrum of AWS services and custom log groups were not fully addressed. The implementation of Custom Logs is Splunk's response to this challenge.

EC2 Logs Ingestion into Splunk

For users interested in leveraging our Custom Logs feature, we have prepared guided walkthroughs of two sample use cases. These examples will help you understand how the feature works.

1. Prepare EC2 Logs for CloudWatch

Begin by installing the CloudWatch Logs agent on your EC2 instances. Configure this agent to target specific logs to a designated CloudWatch Logs group.

2. Ingest EC2 Logs with Data Manager Custom Logs

2.1. Create AWS input in Data Manager.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (1)

2.2.Select Custom Logs data source.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (2)

2.3. Complete all the fields on Input Amazon CloudWatch Logs Data Information - Custom Logs.

2.4. There are two new sections on Input Page: Custom Source Type And Onboard log groups.

2.5. Enter Custom Source Type: You can specify a source type to use in Splunk Search.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (3)

2.6.Log Group Onboarding: If the agent configuration was successful, you should be able to view logs from your EC2. You can filter names you want to onboard, or search through all available log groups.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (4)

2.7.Review input details.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (5)

2.8.Now you can check what log groups have been onboarded.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (6)

Lambda Log Integration into Splunk

1.Configure Lambda Logs for CloudWatch - AWS offers automatic integration for AWS Lambda to push logs to CloudWatch which simplifies the initial setup.

2.Setting Up Data Manager for Custom Logs

2.1.Choose 'Amazon CloudWatch Logs - Custom Logs' under new data input.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (7)

2.2.Complete all prerequisites.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (8)

2.3.Complete the required fields in the 'Input Amazon CloudWatch Logs Data Information - Custom Logs' section.

2.4.Define a custom source type if new to Custom Logs.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (9)

2.5.Onboard the desired log groups and review the data input setup.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (10)

2.6.Review and Finish your input setup.

As we've discussed previously, we've only scratched the surface with two use cases, but, as you might have figured it out, the potential applications are vast. Custom Logs empower you to selectively focus on the log groups that are most relevant to your needs. This means no longer having to ingest every log group from a data source, which improves the data ingestion process significantly.

Also, Custom Logs offer the flexibility to incorporate log types that are not yet natively supported by Data Manager. This ensures that your log management system can evolve and adapt, keeping pace with your growing and changing data needs.

Conclusion: Transforming Log Management with Custom Logs

With Custom Logs, your journey in log management is transformed, offering you a level of clarityand control over your AWS environment. This feature enriches the variety of log sources available to you, equipping users with more refined tools for effective and scalable log analysis. Whether dealing with conventional EC2 instances or other AWS services, the Custom Logs feature in Data Manager is an invaluable asset for holistic log management.

Are you ready to take your log management to the next level? Explore the full capabilities of Custom Logs and start refining your AWS monitoring today. Unlock the full potential of your data with tailored, efficient, and scalable solutions right now. Custom Logs are available with Data Manager 1.9.0+.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (11)

Antoni Komorowski

Antoni is a seasoned Product Manager who oversees cloud data ingestion and brings more than five years of product management experience to Splunk. Prior to this role, Antonihoned his skills as an investment banker in the financial district of London City.

Splunk Data Manager’s Custom Logs: Expanding AWS Log Ingestion Capabilities | Splunk (2024)

References

Top Articles
$25 OFF On Orders $175+
Drunk and Stupid (but painfully honest) - Chapter 4 - entowento - 崩坏:星穹铁道
Your Blog - Sheri Blonde
Fantasy football rankings 2024: Sleepers, breakouts, busts from model that called Deebo Samuel's hard NFL year
Creglist Tulsa
Equinox 63Rd Street Class Schedule Pdf
Large Pawn Shops Near Me
Tear Of The Kingdom Nsp
Tamilyogi Download 2021
2014 Can-Am Spyder ST-S
The 10 Best Drury Hotels in the United States
Entegra Forum
Sauce 423405
Ttw Cut Content
Dr Bizzaro Bubble Tea Menu
Does Publix Have Sephora Gift Cards
Gebrauchte New Holland T6.145 Deluxe - Landwirt.com
Downloahub
Berkeley Law Bookstore
Unveiling The Fascination: Makayla Campinos Video
Indian Restaurants In Cape Cod
Q102 Snow Desk
Fishweather
Kira Kener 2022
Sloansmoans Many
Reptile Expo Spokane
Ella Phipps Haughton
Fast X Showtimes Near Evo Cinemas Creekside 14
Pillowtalk Leaked
Realidades 2 Capitulo 2B Answers
Southeast Ia Craigslist
Verizon Fios Internet Review: Plans, Prices And Speed 2024
Official Klj
France 2 Journal Télévisé 20H
This Is The Right Order To Watch Every X-Men Movie - Looper
Fx Channel On Optimum
Rachel Pizzolato Age, Height, Wiki, Net Worth, Measurement
Tamilrockers 2023 Tamil Movies Download Kuttymovies
Mvsu Canvas
Exterior Ballistics Calculator
Craigslist Houses For Rent In Juneau Alaska
Directions To 401 East Chestnut Street Louisville Kentucky
Filmy4 Web Xyz.com
Watch Shark Tank TV Show - ABC.com
Alger Grade Ohm
Loss Payee And Lienholder Addresses And Contact Information Updated Daily Free List Gm Financial Lea
76 Games Unblocked Fnf
Ttw Cut Content
Computer Repair Arboretum North Carolina
Directions To Lubbock
Omaha World-Herald from Omaha, Nebraska
O2 Fitness West Ashley Photos
Latest Posts
Article information

Author: Corie Satterfield

Last Updated:

Views: 6236

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Corie Satterfield

Birthday: 1992-08-19

Address: 850 Benjamin Bridge, Dickinsonchester, CO 68572-0542

Phone: +26813599986666

Job: Sales Manager

Hobby: Table tennis, Soapmaking, Flower arranging, amateur radio, Rock climbing, scrapbook, Horseback riding

Introduction: My name is Corie Satterfield, I am a fancy, perfect, spotless, quaint, fantastic, funny, lucky person who loves writing and wants to share my knowledge and understanding with you.