We are wanting to use Cribl to repopulate cloud trail logs from S3 into Splunk on-demand for review/audit/analysis purposes. Ideally, we would be able to request from within Splunk, but we could also query within Cribl to pull the data if necessary. Are there any best practices or use-cases that you can provide?
Question
Best way to repopulate S3 data into Splunk?
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
