Data models for the Splunk App for AWS
The Splunk App for AWS includes five data models to support dashboard performance.
Name | Purpose | Accelerated | Action required |
---|---|---|---|
CloudFront Access Log | Supports the Overview and CloudFront - Traffic Analysis dashboards. | Yes | None |
S3 Access Log | Supports the S3 - Traffic Analysis dashboard. | Yes | None |
VPC Flow | Supports the VPC Flow Logs - Traffic Analysis and VPC Flow Logs - Security Analysis dashboards. | Yes | If you ingest high volume VPC flow log data through the Splunk Add-on for AWS's Kinesis input and encounter issues with bundle replication or data model acceleration performance, reduce the data model's summary range to one day. |
Detailed Billing | Supports the Historical Detailed Bills dashboard. | Yes | None |
Instance Hour | Supports the Capacity Planner dashboard. | Yes | None |
Lookups for the Splunk App for AWS | Macros for the Splunk App for AWS |
This documentation applies to the following versions of Splunk® App for AWS (Legacy): 4.2.0, 4.2.1
Feedback submitted, thanks!