Stream AWS S3 logs into Splunk.
Deployed in minutes — searchable in minutes.
The Inno Streaming Add-on for AWS S3 lets a Splunk administrator deploy a serverless AWS Lambda into the customer's own AWS account — no AWS console, no CLI, no Heavy Forwarders — that streams S3 objects into Splunk over HTTP Event Collector (HEC) the moment they land. There is no polling interval to wait for: every new object fires its own event, so data that hits S3 is typically searchable in Splunk within a minute. Daily volume is effectively uncapped — throughput scales linearly, and your Splunk tier becomes the limit long before the add-on does.
Instant email delivery of key + download · S3 → searchable in minutes · Effectively unlimited daily volume · gzip / zstd / bzip2 / plain · NDJSON, whole-file JSON & text logs · Flat $11/month, no per-GB fees · Serverless, no Heavy Forwarders · AWS keys never stored in Splunk · AppInspect cloud-vetted · Splunk Cloud & Enterprise
See pricingWhat it does
One-click deploy from the Search Head
Install on your Splunk Search Head, fill in a short form, and click Deploy. The add-on provisions the Lambda, its IAM role, and the S3 event trigger for you through the AWS API — no console clicking, no CloudFormation, no shell scripts.
Event-driven: S3 → Lambda → HEC
Every ObjectCreated event triggers a compiled Go Lambda that streams,
decompresses, and batches your objects straight to your HEC endpoint. No polling, no queue
latency — events land in Splunk within seconds.
Runs entirely in your AWS account
Nothing passes through our servers. The Lambda runs inside the customer's own AWS account and data flows directly from S3 to your Splunk — Inno Software never sees it.
AWS keys are never stored in Splunk
Your AWS credentials are used only at deploy time to create the resources — then the add-on auto-wipes them (a default "delete credentials after deploy" option), and you can clear them yourself at any time. The running Lambda authenticates with its own least-privilege IAM role, so no long-lived AWS keys are ever retained in Splunk.
Serverless — no forwarder fleet
No Heavy Forwarders to size, run 24/7, or patch. Lambda scales with your data and back to zero when idle — AWS runs it for you, and you pay only for what you ingest.
Battle-tested, secure & air-gap ready
A compiled Go binary (source not shipped), corporate-proxy support, an exportable self-contained deploy script, and fully offline RSA license verification — no phone-home. Extensively benchmarked for stability at scale (see below).
Deploy in three steps
No AWS expertise required. A Splunk admin can go from install to live ingestion in about ten minutes.
- Install on your Search Head. The add-on is a management console, not a data-collection node — data flows S3 → Lambda → HEC directly, so it belongs on the Search Head where admins work, not on a Heavy Forwarder. Works on Splunk Cloud (Victoria) and Splunk Enterprise alike.
- Fill in the form. AWS credentials (used once, then wiped), your license key, and the target: S3 bucket, HEC endpoint, token, and index.
- Click Deploy. The add-on builds the Lambda, IAM role, and S3 trigger in your account. New objects start flowing into Splunk immediately — and you can preview or export the exact deployment plan first.
Speed: from S3 to searchable in minutes
Ingestion is event-driven, not scheduled. Each ObjectCreated
notification invokes the Lambda immediately, so there is no polling interval sitting between
your data and your index — the delay is just the time to stream the object.
| Step | Typical time |
|---|---|
S3 ObjectCreated → Lambda invoked | ~1 second |
| Stream + gunzip + POST a 128 MiB object (1769 MB memory) | ≈ 10 seconds |
| …the same object at the out-of-the-box default (512 MB) | ≈ 33 seconds |
| HEC ingest → searchable in Splunk | seconds |
| End to end, object lands → searchable | usually under a minute |
Objects are processed in parallel, so a burst of new objects does not queue up behind one another — each gets its own invocation. Very large objects take proportionally longer to stream, which is why we quote minutes rather than seconds as the safe expectation.
Throughput: effectively unlimited daily volume
At the recommended 1769 MB memory setting, each Lambda invocation forwards 1.23 TB/day (14.2 MB/s), and throughput scales linearly with reserved concurrency — measured at 24.9 TB/day at concurrency 20, 62 TB/day at 50, and 125 TB/day at 100, continuing past 1 PB/day at the AWS account concurrency ceiling. There is no per-day cap in the add-on: in practice your Splunk indexing tier becomes the limit long before the add-on does. And whatever volume you scale to, the license stays a flat $11/month — there are no per-GB or per-event fees.
| Target throughput (1769 MB, gzip on) | Reserved concurrency |
|---|---|
| 10 TB/day | 9 |
| 100 TB/day | 82 |
| 500 TB/day | 408 |
| 1,000 TB/day | 816 |
Prefer not to tune anything? The out-of-the-box default (512 MB memory, concurrency 20) delivers ≈ 7 TB/day with zero configuration. Raising memory to 1769 MB makes each invocation ~3.5× faster, so higher targets need far less concurrency (the table above).
Benchmark: controlled forwarding test (128 MiB objects, us-east-1), gzip-on measurements only. The synthetic test data compressed ~3.7× under gzip (high-entropy hashes/UUIDs); real-world security logs compress ~8–10×, so egress savings in production are even greater. End-to-end throughput is ultimately bounded by your Splunk indexing tier — the add-on itself is not the limiting factor.
Pricing
Effectively unlimited S3 ingestion — for a flat $11/month.
Our license is one flat price per AWS account: $11/month, or $110/year. There are no per-GB, per-event, or per-ingest fees — ever. Stream 1 GB/day or scale Lambda concurrency to petabytes per day — you pay Inno Software the exact same $11. Throughput scales linearly and is bounded only by your AWS concurrency quota and your Splunk indexing tier, not by us.
The only volume-based cost is the AWS Lambda compute you use directly (≈ $0.002/GB, paid to AWS) — there is no metered charge from us on top of the flat license.
After checkout your license key and the add-on download link are emailed to you automatically, normally within a few minutes — from support@innosw.net. Please check your spam / junk folder if you don't see it.
Annual — 2 months free
- Unlimited ingest volume — no per-GB fees
- Licensed per AWS account (node-locked)
- All updates during the subscription term
- Email support
- Cancel anytime before renewal
Monthly
- Unlimited ingest volume — no per-GB fees
- Licensed per AWS account (node-locked)
- All updates while subscribed
- Email support
- Cancel anytime
📧 Delivered to your inbox — instantly, automatically
The moment your payment completes, we email the address you used at checkout with both:
- Your license key — already node-locked to the AWS account ID you entered, ready to paste into the add-on
- The add-on download link — plus step-by-step install instructions
No waiting, no support ticket, no manual step — the whole thing is automated. The email is sent the instant the payment clears and normally reaches you within a few minutes.
Need multiple AWS accounts, an enterprise agreement, or a proof-of-concept license? Get in touch.
Payments are processed by Paddle.com, our merchant of record. Applicable taxes/VAT are handled at checkout.
FAQ
How do I get the add-on and my license key after paying?
Both are emailed to you automatically, within a few minutes of your payment completing — the download link for the add-on and your license key (already locked to the AWS account ID you entered at checkout), with install steps. If it isn't in your inbox, check your spam/junk folder — it comes from support@innosw.net. You can always email us and we'll resend it.
Where should I install the add-on?
On your Search Head. The add-on is a management/deployment console — it does not collect data itself, so it does not belong on a Heavy Forwarder. Once deployed, data flows S3 → Lambda → HEC directly to your indexers, independent of the add-on. Works on Splunk Cloud (Victoria) and Splunk Enterprise.
Are my AWS credentials stored in Splunk?
No long-lived keys are retained. Credentials are needed only at deploy time to create the AWS resources; the add-on wipes them automatically after a successful deploy (on by default) and you can clear them manually at any time. The deployed Lambda runs on its own least-privilege IAM role, not on your keys.
Does my data pass through your servers?
No. The Lambda runs in your own AWS account and sends data directly to your Splunk HEC endpoint. Inno Software never sees your data.
Which Splunk versions are supported?
Splunk Cloud (Victoria Experience) and Splunk Enterprise 9.x with Python 3. The add-on passes Splunk AppInspect cloud checks.
What object formats are supported?
Compression — gzip, zstd, bzip2, or uncompressed. Detected from the file's magic bytes, never the file extension, so a mislabelled or extension-less object still works. Everything is streamed, so memory stays flat regardless of object size.
Structure — auto-detected, no configuration:
- NDJSON / JSON Lines → one event per line, indexed as structured JSON; the configured time and host fields are lifted into Splunk metadata.
- Whole-file JSON — a
{"Records":[…]}envelope (CloudTrail style, even with no newlines at all) or a bare JSON array → streamed with a JSON decoder that emits one event per element at constant memory. Large integers keep their precision. - Plain-text lines (syslog, CSV,
key=value, ALB and VPC Flow access logs) → sent to HEC/rawexactly as written, with an option to skip a header line. No line is dropped.
Per-prefix routing — map S3 key prefixes to different indexes and sourcetypes (longest prefix wins), so CloudTrail, VPC Flow and application logs can land in the right place from a single bucket. Routes are validated at deploy time, so a typo is a UI error rather than a 3 a.m. mis-route.
Verified end-to-end — every format below was tested at 500 events in, 500 events indexed, zero loss:
| Source shape | Compression | HEC endpoint | Result |
|---|---|---|---|
CloudTrail {"Records":[…]}, single line, no newlines | gzip | /event | 500 / 500 |
| Bare JSON array | gzip | /event | 500 / 500 |
| NDJSON | zstd | /event | 500 / 500 |
| NDJSON | none (.jsonl) | /event | 500 / 500 |
| ALB access logs (text) | gzip | /raw | 500 / 500 |
| VPC Flow Logs (text, with header) | gzip | /raw + skip header | 500 / 500 |
Typical sources — CloudTrail, VPC Flow Logs, ALB/CloudFront access logs, GuardDuty, Kinesis Firehose, and most EDR/security and application log shippers.
Not supported (contact us) — columnar/binary formats (Parquet, Avro, ORC) and multiline-per-event logs.
Does licensing require internet access?
No. License keys are RSA-signed and verified locally — ideal for air-gapped environments. Keys are locked to your AWS account ID(s).
What happens when my subscription ends?
The license includes a grace period after expiry. After the grace period, ingestion stops until the license is renewed. Your deployed AWS resources remain under your control.