Skip to main content
Splunk Add-on for Amazon Web Services app icon

Splunk Add-on for Amazon Web Services

The Splunk Add-on for Amazon Web Services allows a Splunk® software administrator to collect events, alerts, performance metrics, configuration snapshots, and billing information from the CloudWatch, CloudTrail, and Config services. It can also gather log data from CloudWatch Logs, including VPC Flow Logs, and AWS billing reports and generic log files from S3 buckets. This add-on provides modular inputs and CIM-compatible knowledge to use with other Splunk apps, such as the Splunk App for AWS and Splunk Enterprise Security.Built by Splunk LLC
splunk product badge

Default Version 8.2.1

July 30, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 9.5

CIM Version: 5.x

Rating
5
(10)

Log in to rate this app

Support
Splunk Supported
Ranking

#18 in Security, Fraud & Compliance

#28 in IT Operations

The Splunk Add-on for Amazon Web Services allows a Splunk® software administrator to collect events, alerts, performance metrics, configuration snapshots, and billing information from the CloudWatch, CloudTrail, and Config services. It can also gather log data from CloudWatch Logs, including VPC Flow Logs, and AWS billing reports and generic log files from S3 buckets. This add-on provides modular inputs and CIM-compatible knowledge to use with other Splunk apps, such as the Splunk App for AWS and Splunk Enterprise Security. Only CloudTrail, CloudWatch, VPC Flow Log, and Config data is tagged for CIM compliance. Because data gathered from S3 buckets is not predictable, the add-on can not normalize it to the CIM data models.