TL;DR
The existing AWS Blog approach ships FSx for ONTAP audit logs to Splunk via two EC2 instances (syslog-ng + Universal Forwarder). We replaced it with a single Lambda function — same Splunk index, same SPL queries, 90% AWS infrastructure cost reduction.
[Before] FSx for ONTAP → syslog-ng (EC2) → Splunk UF (EC2) → Splunk
Monthly AWS infra cost: ~$66 (2× t3.medium + EBS)
Ops burden: OS patching, agent updates, scaling










