<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk For AWS Problem in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164814#M15552</link>
    <description>&lt;P&gt;Hi Nilesh&lt;BR /&gt;
I upgraded to Splunk 6.0 and I now have the aws-cloudtrail data input, I configured it with the Key ID, Secret Key, SQS Queue Name and region, I then ran the Splunk for AWS app but get "No results found" on all of the panels, I did configure the s3 bucket and when I go to it I can see that it is populated with logs but the Splunk for AWS apparently is not connecting to it.  What's worse is that there is nothing in the logs to indicate if there is a problem.  Suggestions?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2013 18:23:31 GMT</pubDate>
    <dc:creator>bruceav</dc:creator>
    <dc:date>2013-12-05T18:23:31Z</dc:date>
    <item>
      <title>Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164808#M15546</link>
      <description>&lt;P&gt;When I try running the Splunk For AWS app I get the following error:&lt;/P&gt;

&lt;P&gt;Splunk cannot find the "AWSCloudTrail-overview" view.&lt;/P&gt;

&lt;P&gt;As far as I know the aws.conf is configured correctly and my Cloudtrail bucket is configured correctly.  What am I missing?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 17:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164808#M15546</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-03T17:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164809#M15547</link>
      <description>&lt;P&gt;There are two portions of this app.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Billing and Usage &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;CloudTrail&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;aws.conf is used for Billing and usage portion of the app. and AWS CloudTrail inputs under settings-&amp;gt; Data inputs is used for CloudTrail.&lt;/P&gt;

&lt;P&gt;Have you configured AWS CloudTrail inputs under settings-&amp;gt;Data inputs  ? &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Nilesh&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 18:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164809#M15547</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-03T18:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164810#M15548</link>
      <description>&lt;P&gt;Nilesh, Thanks for your response. I tried setting the Data Inputs section but nothing there shows up by the name of CloudTrail and the instructions are not specific as to whether I should create one by that name and if so what kind of input (TCP, UDP, file,etc...)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 19:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164810#M15548</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-03T19:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164811#M15549</link>
      <description>&lt;P&gt;If you do not see AWS CloudTrail Log type under Settings -&amp;gt; Data inputs,  there could be installation issue with AWS App. &lt;/P&gt;

&lt;P&gt;If you are online, skype me on &lt;A href="mailto:nkhetia@hotmail.com"&gt;nkhetia@hotmail.com&lt;/A&gt; and we can figure it out, real quick. &lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
Nilesh&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 20:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164811#M15549</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-03T20:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164812#M15550</link>
      <description>&lt;P&gt;I wish I could skype but I'm not allowed to install Skype in the office workstation.  I did however go back to check my installation and noticed that the files were owned by root so I chowned them to splunk, that however did not fix the problem.  As I restarted Splunk I noticed that there were several errors popping on the screen with the message "Possible typo in stanza [aws-cloudtrail] in $SPLUNK_HOME/etc/apps/SplunkforAWS/default/inpiuts.conf"&lt;BR /&gt;
I think it may have to do with the version of Splunk I'm running (4.3.1)  So I'm going to update my Splunk and try again.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 20:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164812#M15550</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-03T20:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164813#M15551</link>
      <description>&lt;P&gt;yes .. it requires splunk 6.0. &lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
Nilesh&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 21:34:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164813#M15551</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-03T21:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164814#M15552</link>
      <description>&lt;P&gt;Hi Nilesh&lt;BR /&gt;
I upgraded to Splunk 6.0 and I now have the aws-cloudtrail data input, I configured it with the Key ID, Secret Key, SQS Queue Name and region, I then ran the Splunk for AWS app but get "No results found" on all of the panels, I did configure the s3 bucket and when I go to it I can see that it is populated with logs but the Splunk for AWS apparently is not connecting to it.  What's worse is that there is nothing in the logs to indicate if there is a problem.  Suggestions?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 18:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164814#M15552</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-05T18:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164815#M15553</link>
      <description>&lt;P&gt;Hi Bruce,&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;If you are using credentials of IAM user, that IAM user should have enough permissions to access S3 data.&lt;/LI&gt;
&lt;LI&gt;Do you see messages queued up under SQS in AWS Management Console ?&lt;/LI&gt;
&lt;LI&gt;Also while configuring CloudTrail inputs,  have you specified following things ?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Select More Settings checkbox.&lt;/P&gt;

&lt;P&gt;Set Source type as Manual  and specify aws-cloudtrail as Source type.&lt;BR /&gt;
 Under index, select destination index as aws-cloudtrail.&lt;/P&gt;

&lt;P&gt;thx&lt;/P&gt;

&lt;P&gt;Nilesh&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 18:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164815#M15553</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-05T18:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164816#M15554</link>
      <description>&lt;P&gt;The IAM user has AWSCloudTrailFullAccess under Permissions, as for the SQS there are no messages.&lt;BR /&gt;
I set Sourcetype to manual but don't know what I should put in the "Source Type" field.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 18:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164816#M15554</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-05T18:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164817#M15555</link>
      <description>&lt;P&gt;if there are no messages in SQS, make sure it is subscribed to correct sns topic.  Please check this link : &lt;A href="http://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqssubscribe.html"&gt;http://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqssubscribe.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Under manual sourcetype, specify "aws-cloudtrail".&lt;/P&gt;

&lt;P&gt;thx&lt;/P&gt;

&lt;P&gt;Nilesh&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 19:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164817#M15555</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-05T19:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164818#M15556</link>
      <description>&lt;P&gt;So it was not subscribed to an sns topic but now it is, thanks for that hint, but I am getting messages in the SQS but still nothing in the app.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 19:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164818#M15556</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-05T19:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164819#M15557</link>
      <description>&lt;P&gt;Hi Bruce,  could you send your contact details to &lt;A href="mailto:nkhetia@splunk.com"&gt;nkhetia@splunk.com&lt;/A&gt; ?   I will try and setup webex to troubleshoot it.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;

&lt;P&gt;Nilesh&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 20:14:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164819#M15557</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-05T20:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164820#M15558</link>
      <description>&lt;P&gt;I appreciate that but unfortunately we are not allowed to have any type of VTC connections from where I work.  The documentation doesn't say anything about port being used by Splunk for AWS, does it use a separate port or is it going out on the same port the Splunk uses?  Just curious if my firewall may be blocking Splunk for AWS.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 20:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164820#M15558</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-05T20:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164821#M15559</link>
      <description>&lt;P&gt;It uses same port.  It could be api call to aws are blocked.  Can you try using cloudtrail2splunk.py under bin folder?  Its manual way to ingest cloudtrail data in splunk. You can refer to USAGE.txt.&lt;/P&gt;

&lt;P&gt;To use billing &amp;amp; usage, aws.conf needs to be configured.  Please refer to README.txt.  If it is getting data, api call to aws are not blocked.&lt;/P&gt;

&lt;P&gt;thx&lt;BR /&gt;
Nilesh&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 20:32:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164821#M15559</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-05T20:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164822#M15560</link>
      <description>&lt;P&gt;Hi Nilesh, took a break last Friday on troubleshooting this issue to concentrate on other issues at work, and to relieve my frustration that this isn't working yet, but hopefully you can help me get this working today.&lt;BR /&gt;
Still in same situation where my "AWS Cloudtrail Log" seems to be configured correctly but I'm still not getting any of the messages from the SQS to Splunk and the SQS has over 500 messages now.  Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 14:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164822#M15560</guid>
      <dc:creator>bruceav</dc:creator>
      <dc:date>2013-12-09T14:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164823#M15561</link>
      <description>&lt;P&gt;Hi Bruce,&lt;/P&gt;

&lt;P&gt;Sure, lets go through the checklist once again in order to verify your setup.  Before we do that, can you shoot me an email to &lt;A href="mailto:nkhetia@splunk.com"&gt;nkhetia@splunk.com&lt;/A&gt;, so that i can send you some sample screenshots  ?&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt; Remove cloudtrail setup entry which is already there from last week.&lt;/LI&gt;
&lt;LI&gt; add new configuration using same IAM user credentials&lt;/LI&gt;
&lt;LI&gt;make sure IAM user is power/admin user who has all grants&lt;/LI&gt;
&lt;LI&gt;SQS region and queue name should be identical to one which you setup manually&lt;/LI&gt;
&lt;LI&gt;Also while configuring CloudTrail inputs, specify following things:&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Select More Settings checkbox.&lt;/P&gt;

&lt;P&gt;Set Source type as Manual  and specify "aws-cloudtrail" as Source type.&lt;/P&gt;

&lt;P&gt;Under index, select destination index as "aws-cloudtrail".&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;In Splunk search bar, try searching for events by index=*, and see if you see any json data. &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;You can also try ingesting CloudTrail data using cloudtrail2splunk.py under bin folder.  Please refer USAGE.txt to use the same. &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Have you tried setting up aws.conf for Billing data ? if so, do you see any data coming in under Billing &amp;amp; Usage dashboards?&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Nilesh&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 19:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164823#M15561</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-09T19:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164824#M15562</link>
      <description>&lt;P&gt;I got my Cloudtrail logs into SplunkAppforAWS with a small change in aws-cloudtrail.py.&lt;/P&gt;

&lt;P&gt;Background:  Cloudtrail data wasn't feeding into my dashboards, and I saw a steady stream of errors in $SPLUNK_HOME/var/log/splunk/splunkd.log.  Same error message:  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-10-2014 04:53:56.015 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py" KeyError: 'Message'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The solution was to edit $SPLUNK_HOME/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py. I commented out one line, and replaced it with another.  Now this appears about 200 lines down in my file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    #message = json.loads(envelope["Message"])
    message = envelope
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Make this change, and in a few minutes, the errors in the splunkd.log disappear, and data begins to populate the dashboards.  &lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;BR /&gt;
-Pete&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 15:04:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164824#M15562</guid>
      <dc:creator>grinabms</dc:creator>
      <dc:date>2014-03-14T15:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164825#M15563</link>
      <description>&lt;P&gt;Did you change anything else in the script? I tried your suggestion and it produced same type of error for MessageId..&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 22:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164825#M15563</guid>
      <dc:creator>atanasoffa</dc:creator>
      <dc:date>2014-04-30T22:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164826#M15564</link>
      <description>&lt;P&gt;That's the only change that I made.  Can you post your error message?  &lt;/P&gt;

&lt;P&gt;One suggestion is to add a debugging line to see exactly what is in the "envelope"... here is how it should look:&lt;BR /&gt;
            logging.info("envelope: %s",json.dumps(envelope))&lt;BR /&gt;
            #message = json.loads(envelope["Message"])&lt;BR /&gt;
            message = envelope&lt;/P&gt;

&lt;P&gt;When you save the edit, then your splunkd.log file should contain log entries like this:&lt;/P&gt;

&lt;P&gt;03-25-2014 23:25:54.726 +0000 INFO  ExecProcessor - message from "python /opt/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py" envelope: {"s3ObjectKey": ["AWSLogs/123412341234/CloudTrail/us-east-1/2014/03/24/123412341234_CloudTrail_us-east-1_20140324T1645Z_pUiRsGvGTkwgBOoL.json.gz"], "s3Bucket": "my-log-bucket"}&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:31:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164826#M15564</guid>
      <dc:creator>grinabms</dc:creator>
      <dc:date>2020-09-28T16:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For AWS Problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164827#M15565</link>
      <description>&lt;P&gt;Thanks for your reply.  Here are some of my errors after I applied your suggestion:&lt;/P&gt;

&lt;P&gt;05-05-2014 18:10:00.495 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py"   File "/apps/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py", line 219, in run&lt;/P&gt;

&lt;P&gt;05-05-2014 18:10:00.495 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py"     logging.debug("reading message with id %s at %s",envelope["MessageId"],envelope["Timestamp"])&lt;/P&gt;

&lt;P&gt;05-05-2014 18:10:00.495 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py" KeyError: 'MessageId'&lt;/P&gt;

&lt;P&gt;I added in a debug line and I do get similar output as you, just in a different order (the "s3bucket" object and value is before the s3ObjectKey) but then I get the errors above...&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 18:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-For-AWS-Problem/m-p/164827#M15565</guid>
      <dc:creator>atanasoffa</dc:creator>
      <dc:date>2014-05-05T18:23:33Z</dc:date>
    </item>
  </channel>
</rss>

