<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AWS Add on unable to parse CloudTrail data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136776#M11534</link>
    <description>&lt;P&gt;I have an issue where I get the error,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;DEBUG pid=11513 tid=MainThread file=aws_cloudtrail.py:stream_events:210 | Connect to S3 &amp;amp; Sqs sucessfully
 2015-02-12 19:23:56,799 CRITICAL pid=11513 tid=MainThread file=aws_cloudtrail.py:stream_events:286 | Outer catchall: TypeError: 'int'            object has no attribute '__getitem__'
 2015-02-12 19:23:56,799 INFO pid=11513 tid=MainThread file=aws_cloudtrail.py:&amp;lt;module&amp;gt;:419 | EXITED: 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And on Splunkd.log I see a generic error,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-12-2015 19:36:27.297 +0000 ERROR ExecProcessor - message from "python /splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudtrail.py" ERROR'int' object has no attribute '__getitem__'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It looks like Splunk is getting the logs to its indexes from AWS as I do a search on Splunk I can see JSON format logs there but the AWS add on is unable to parse the data and generate meaningful reports spewing out the above errors. &lt;BR /&gt;
Can you guys help? I'm using the latest version of Splunk on Amazon Linux if that helps. &lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2015 19:38:44 GMT</pubDate>
    <dc:creator>kkossery</dc:creator>
    <dc:date>2015-02-12T19:38:44Z</dc:date>
    <item>
      <title>AWS Add on unable to parse CloudTrail data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136776#M11534</link>
      <description>&lt;P&gt;I have an issue where I get the error,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;DEBUG pid=11513 tid=MainThread file=aws_cloudtrail.py:stream_events:210 | Connect to S3 &amp;amp; Sqs sucessfully
 2015-02-12 19:23:56,799 CRITICAL pid=11513 tid=MainThread file=aws_cloudtrail.py:stream_events:286 | Outer catchall: TypeError: 'int'            object has no attribute '__getitem__'
 2015-02-12 19:23:56,799 INFO pid=11513 tid=MainThread file=aws_cloudtrail.py:&amp;lt;module&amp;gt;:419 | EXITED: 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And on Splunkd.log I see a generic error,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-12-2015 19:36:27.297 +0000 ERROR ExecProcessor - message from "python /splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudtrail.py" ERROR'int' object has no attribute '__getitem__'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It looks like Splunk is getting the logs to its indexes from AWS as I do a search on Splunk I can see JSON format logs there but the AWS add on is unable to parse the data and generate meaningful reports spewing out the above errors. &lt;BR /&gt;
Can you guys help? I'm using the latest version of Splunk on Amazon Linux if that helps. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 19:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136776#M11534</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2015-02-12T19:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Add on unable to parse CloudTrail data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136777#M11535</link>
      <description>&lt;P&gt;Thank you jcoates_splunk for your response to another thread. He responded by,&lt;BR /&gt;
    "every time i've seen that sort of error message it's meant that the add-on is being directed to gather "cloudtrail" data from a bucket that actually contains something else."&lt;/P&gt;

&lt;P&gt;Here is my response - The cloudtrail folder was created specifically for this purpose and do not have any other data. Is there any other suggestions that I need to try out? Thank you again. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 19:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136777#M11535</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2015-02-12T19:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Add on unable to parse CloudTrail data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136778#M11536</link>
      <description>&lt;P&gt;After re-doing my Splunk Install and SQS, SNS, CloudTrail setup, I see some improvement. On aws_CloudTrail Log,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-02-13 11:03:44,241 INFO pid=25836 tid=MainThread file=aws_cloudtrail.py:process_notifications:356 |    processing 4 records in s3:trailertruck/AWSLogs/2xxxxxxx/CloudTrail/us-east-1/2015/02/13/xxxxxxxx_CloudTrail_us-east-1_20150213T1605Z_0YodSeqjgEBI0nqU.json.gz
2015-02-13 11:03:44,241 DEBUG pid=25836 tid=MainThread file=aws_cloudtrail.py:process_notifications:369 | writing event DescribeLoadBalancers with timestamp 2015-02-13T16:00:02Z
2015-02-13 11:03:44,242 DEBUG pid=25836 tid=MainThread file=aws_cloudtrail.py:process_notifications:369 | writing event CreateKeyPair with timestamp 2015-02-13T15:59:25Z
2015-02-13 11:03:44,243 DEBUG pid=25836 tid=MainThread file=aws_cloudtrail.py:process_notifications:369 | writing event DescribeAlarms with timestamp 2015-02-13T15:59:11Z
2015-02-13 11:03:44,243 DEBUG pid=25836 tid=MainThread file=aws_cloudtrail.py:process_notifications:369 | writing event DeleteKeyPair with timestamp 2015-02-13T15:59:49Z
2015-02-13 11:03:44,244 INFO pid=25836 tid=MainThread file=aws_cloudtrail.py:process_notifications:393 | fetched 4 records, wrote 4, discarded 0, redirected 0 from s3:trailertruck/AWSLogs/2xxxxxxx/CloudTrail/us-east-1/2015/02/13/2xxxxxxxxx_CloudTrail_us-east-1_20150213T1605Z_0YodSeqjgEBI0nqU.json.gz
2015-02-13 11:03:44,256 INFO pid=25836 tid=MainThread file=aws_cloudtrail.py:stream_events:283 | 1 completed, 0 failed while processing a notification batch of 1 [0 errors deleting 1 notifications]  Elapsed: 0.077s
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, on splunkd.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-13-2015 10:55:36.381 -0500 WARN  SearchOperator:inputcsv - Encountered 1 'inconsistent number of column' errors while reading input.
    02-13-2015 10:55:36.791 -0500 WARN  SearchOperator:inputcsv - Encountered 1 'inconsistent number of column' errors while reading input.
    02-13-2015 10:55:36.809 -0500 WARN  SearchOperator:inputcsv - Encountered 1 'inconsistent number of column' errors while reading input.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm not sure what to make of it but I'm going to dig deeper and see if I can come up with something else. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 16:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136778#M11536</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2015-02-13T16:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Add on unable to parse CloudTrail data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136779#M11537</link>
      <description>&lt;P&gt;After spending time on the Splunk forums and finding this link, this has been resolved. I had to create an index named aws-cloudtrail manually and load the data in it. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/205803/aws-cloudtrail-data-not-shown-in-the-dashboard-und.html"&gt;http://answers.splunk.com/answers/205803/aws-cloudtrail-data-not-shown-in-the-dashboard-und.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 16:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-Add-on-unable-to-parse-CloudTrail-data/m-p/136779#M11537</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2015-02-13T16:58:39Z</dc:date>
    </item>
  </channel>
</rss>

