About Federated Search for Cloud Watch Unified Data Store

Federated Search for CloudWatch Unified Data Store lets you search CloudWatch log data from your Splunk Cloud Platform deployment, without indexing or ingesting it first.

Amazon CloudWatch Unified Data Store is an AWS Cloud service that centralizes metrics, logs, and traces from AWS services and third-party sources into a single location to simplify observability, security, and compliance analytics.

Federated Search for CloudWatch Unified Data Store lets you search CloudWatch log data from your Splunk Cloud Platform deployment, without indexing or ingesting it first, using familiar SPL2 search commands and syntax.

Use the results of your CloudWatch queries to investigate activity in your AWS environment, explore historical logs, and correlate CloudWatch data and telemetry with data already available in your local Splunk indexes.

Connections and datasets

Federated Search for CloudWatch Unified Data Store is part of the Data Management app, where you'll set up your federated search experience through the definition of connections and datasets.
Connection
A CloudWatch Unified Data Store connection defines how Splunk software securely authenticates a link between your Splunk Cloud Platform deployment and a federated dataset in an Amazon S3 table. Connections are reusable and can be associated with multiple CloudWatch Unified Data Store datasets. CloudWatch Unified Data Store connections do not specify what data is searchable.
Dataset
A CloudWatch Unified Data Store dataset is a searchable data object that is associated with a single CloudWatch Unified Data Store connection. Each CloudWatch Unified Data Store dataset is defined by its association with an Amazon S3 table that contains CloudWatch data you want to search.

What you need to get started

  • You must have a Splunk Cloud Platform (SCP) deployment that is hosted on AWS (Amazon Web Services).

  • Your user account on the SCP deployment must have a role with the edit_connections and edit_datasets capabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual.
  • You must have an Amazon Web Services (AWS) account and an AWS IAM role with permissions that let you attach and modify custom trust policies and resource policies for IAM roles. Contact your AWS administrator for assistance with AWS permissions. See IAM role creation in the AWS Identity and Access Management User Guide.
  • You must have CloudWatch Unified Data Store data in an S3 table that you want to run federated searches over.

Checklist of tasks to set up Federated Search for CloudWatch Unified Data Store

Use this checklist to guide you through the cross-account setup of Federated Search for CloudWatch Unified Data Store.

Step Task Description
1 Create a CloudWatch Unified Data Store connection A connection contains the tools you need to authenticate the ability to run federated searches over CloudWatch Unified Data Store datasets from your Splunk platform deployment.
2 Define a CloudWatch Unified Data Store dataset Provide baseline information for your CloudWatch Unified Data Store dataset, such as the connection it's associated with, its name and description, the Amazon S3 table that contains the data it represents, and optional time setting information.
3 Set the access policy and permissions for a CloudWatch Unified Data Store dataset Finish creating your CloudWatch Unified Data Store dataset by applying its resource access policy and permissions to the IAM role associated with the dataset's connection.
4 Give your users role-based access control of federated datasets After you have successfully created a CloudWatch Unified Data Store dataset, give your users role-based access to it so they can use it in their federated searches.
5 Run federated searches over federated datasets with SPL2 Run federated searches over your new CloudWatch Unified Data Store dataset with SPL2.