Source

Amazon CloudWatch Logs

Monitor and store log files from AWS and other resources

The Amazon CloudWatch Logs service offers centralized, highly scalable monitoring and storage of log files from Amazon EC2 instances, AWS CloudTrail, Amazon Route 53, and other sources.

Read our Solution Brief

How to get data flowing

Data ingestion from Amazon CloudWatch Logs is facilitated through Cribl Stream’S S3, Kinesis, and/or Kinesis Firehose Sources.

CloudWatch Logs as source and Stream as a destination

  • Configure CloudWatch Logs to export log events to AWS S3 buckets.

  • Specify an Amazon S3 bucket for log storage, granting appropriate permissions to write to the bucket.

  • Configure Stream to read data from S3 via Sources > Amazon S3.
    Supply your SQS queue.

  • IAM roles or manual keys are both supported.

  • LogStream will start fetching data as SQS messages become available.

CloudWatch Logs as Destination and Stream as a source

  • Configure Stream to send data to CloudWatch Logs via Destinations > Amazon CloudWatch Logs.

  • Specify the log group, log stream, AWS Region, and optional parameters.
    Authenticate via keys or IAM role.

  • Stream will start sending data as it becomes available.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.