- Customer is planning on using Splunk Cloud
- They want ALL logs from their Dedicated environments to be sent to Splunk.
- Splunk will only retain 90 days (number of days is not final but it is a short term) worth of log entries. It is cost prohibitive to use Splunk for long term retention.
- They need a cost effective solution for long term retention of logs. They require long term (many years) retention for regulatory and compliance reasons.
- They are considering COS for long term retention.
- They need a way to store ALL logs from their Dedicated environments to a customer provisioned COS.
- They will access the provisioned COS using the S3 APIs and pull the data into other systems for analytics and other purposes.
- So they need ALL application logs sent at the same time to Splunk and to COS.