Source types for the Splunk Add-on for Amazon Kinesis Firehose
The Splunk Add-on for Amazon Kinesis Firehose provides knowledge management for the following Amazon Kinesis Firehose source types:
Data source | Source type | CIM compliance | Description |
---|---|---|---|
CloudTrail events | aws:cloudtrail
|
Change Analysis, Authentication, Change | AWS API call history form the AWS CloudTrail service, delivered as CloudWatch events.
|
CloudWatch events | aws:firehose:cloudwatchevents
|
None | Data from CloudWatch.
|
GuardDuty events | aws:cloudwatch:guardduty
|
Alerts, | GuardDuty events from CloudWatch.
|
Amazon Identity and Access Management (IAM) Access Analyzer events | aws:accessanalyzer:finding
|
None | Using Eventbridge event bus to ingest the events, set the source to aws_eventbridgeevents_iam_aa when configuring the HEC token.
|
Amazon Kinesis Firehose JSON data | aws:firehose:json
|
None | Any JSON formatted Firehose data. |
Amazon Kinesis Firehose text data | aws:firehose:text
|
None | Firehose raw text format. |
AWS Security Hub | aws:securityhub:finding
|
Alerts | Collect events from AWS Security Hub.
|
VPC Flow Logs | aws:cloudwatchlogs:vpcflow
|
Network Traffic | VPC Flow Logs from CloudWatch.
|
About the Splunk Add-on for Amazon Kinesis Firehose | Release notes for the Splunk Add-on for Amazon Kinesis Firehose |
This documentation applies to the following versions of Splunk® Supported Add-ons: released, released
Feedback submitted, thanks!