This blog was co-authored by Ranjit Kalidasan, Senior Solutions Architect at AWS.
We're excited to share a significant update to our AWS Technical Add-on (TA) for Splunk, focusing on a more efficient and cost-effective re-ingestion process for failed data delivery from S3 error buckets. This update is a direct response to popular demands from our Splunk Ideas portal, aiming to optimize operations for our users.
The traditional approach to managing failed data deliveries required a Lambda function to retrieve and process data from S3 error buckets, introducing complexity and additional costs. You can read more about the problem in this blog post.
We have integrated the parsing functionality directly into the AWS TA. This integration substantially streamlines the re-ingestion process and diminishes related expenses.
The AWS TA now autonomously processes both eventData and rawData. Users maintain control over defining the structure and transformations of eventData, while the add-on takes over the responsibility of decoding base64 data. This enhancement eliminates the need for a custom Lambda function, simplifying the data handling process.
Assuming that you have configured the backup settings in your AWS Kinesis Firehose console to store only failed events, this designated bucket will contain events that could not be ingested due to connectivity issues or other barriers preventing data transfer to Splunk.
Create New Input - VPC Flows Logs
Fill the relevant information related to SQS basedS3
An Advanced Settings with ‘Firehose Failed Events’ has been added to our UI. Simply choose the relevant decoder based on their data type.
This will collect all events which were stored in the s3 bucket because of the error.
These enhancements help customers in two key ways:
This enhancement is a testament to our commitment to continually improving the user experience and operational efficiency. We eagerly anticipate your feedback and are excited to see the positive effects of this new feature on your operations.
We appreciate your involvement in our Splunk community.
For in-depth information, please consult our documentation and join our community forums for discussions and support. Look forward to more exciting updates from us!
The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are secure, resilient and innovative.
Founded in 2003, Splunk is a global company — with over 7,500 employees, Splunkers have received over 1,020 patents to date and availability in 21 regions around the world — and offers an open, extensible data platform that supports shared data across any environment so that all teams in an organization can get end-to-end visibility, with context, for every interaction and business process. Build a strong data foundation with Splunk.