We have a large, expanded network of users that we track using icons. Total traffic is about 60 million impressions per month. We are currently considering moving from a rather slow, database-based logging solution (customizable with PHP-messy ...) to a simple database based on Amazon S3 and Splunk logs.
After using Splunk for some other analysis tasks, I really like it. But it is unclear how to configure a source such as S3 with the system. It seems that remote sources require Universal Forwarder to be installed, and this is not an option.
Any ideas on this?
source
share