TL;DR


The existing AWS Blog approach ships FSx for ONTAP audit logs to Splunk via two EC2 instances (syslog-ng + Universal Forwarder). We replaced it with a single Lambda function — same Splunk index, same SPL queries, 90% AWS infrastructure cost reduction.



[Before] FSx for ONTAP → syslog-ng (EC2) → Splunk UF (EC2) → Splunk
Monthly...