<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Splunk app for AWS&amp;quot; does not allow Cloudtrail Data Input in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165392#M15677</link>
    <description>&lt;P&gt;I did it through the Apps--&amp;gt;Setup - but I was still looking in the splunkd.log for the information.&lt;/P&gt;

&lt;P&gt;I ran the query per the link you sent&lt;/P&gt;

&lt;P&gt;index = _internal source=&lt;EM&gt;aws&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;and I see DEBUG entries - but not errors.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2015 18:25:16 GMT</pubDate>
    <dc:creator>clifforg</dc:creator>
    <dc:date>2015-04-14T18:25:16Z</dc:date>
    <item>
      <title>"Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165380#M15665</link>
      <description>&lt;P&gt;I have configured the AWS CloudTrail with SNS and SQS.&lt;BR /&gt;
Now I try to set up Splunk with Splunk app for AWS.&lt;BR /&gt;&lt;BR /&gt;
However, under "setting-&amp;gt;Data Input", I don't see CloudTrail data input page to enter the security key, secret key, SQS Queue name, and region.&lt;BR /&gt;
I read another similar question, and someone mentioned to update DB Connect App, but it does not help.&lt;BR /&gt;
Could someone help to solve this problem in DETAILs...&lt;BR /&gt;
Thanks a thousand.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 07:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165380#M15665</guid>
      <dc:creator>cchsiang2002</dc:creator>
      <dc:date>2014-12-28T07:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165381#M15666</link>
      <description>&lt;P&gt;Hi, you need to use Splunk Add-on for Amazon Web Services to gather that data.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 15:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165381#M15666</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2014-12-28T15:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165382#M15667</link>
      <description>&lt;P&gt;Thanks a thousands.... It works now.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 16:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165382#M15667</guid>
      <dc:creator>cchsiang2002</dc:creator>
      <dc:date>2014-12-28T16:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165383#M15668</link>
      <description>&lt;P&gt;Now I do see the Data Input for AWS CloudTrail, CloudWatch, AWS Billing, and S3.&lt;BR /&gt;&lt;BR /&gt;
However, there is no AWS accounts for me to select.  There is a help text "Select an AWS account. To configure AWS accounts, go to the setup page.".&lt;BR /&gt;&lt;BR /&gt;
I have problem locate this "setup page". &lt;BR /&gt;
Could someone provide step-by-step instructions to enter my AWS credential?&lt;BR /&gt;
This shouldn't be this difficult to add my AWS credential...&lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 16:45:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165383#M15668</guid>
      <dc:creator>cchsiang2002</dc:creator>
      <dc:date>2014-12-28T16:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165384#M15669</link>
      <description>&lt;P&gt;step by step instructions are in the documentation: &lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/AWS/Installationsteps"&gt;http://docs.splunk.com/Documentation/AddOns/latest/AWS/Installationsteps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 16:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165384#M15669</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2014-12-28T16:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165385#M15670</link>
      <description>&lt;P&gt;The instruction you provided states:&lt;BR /&gt;
"All settings can be configured through Splunk Web or manually in inputs.conf. ".&lt;BR /&gt;
But in the document you provided, I could not find the web page description, e.g. where, and how.&lt;BR /&gt;
As for the manual setup, I follow the instructions, and edited the following files:&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/Splunk_TA_aws/local/inputs.conf&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/Splunk_TA_aws/default/inputs.conf&lt;BR /&gt;
Now I DO see my AWS account in the Add New Data page.  When I selected my aws account that I previously specified in the "inputs.conf", I was asked for the AWS region.  I selected the correct AWS region, and now I am asked for SQS queue name.  But I got the following error:&lt;BR /&gt;
"Failed to fetch data: In handler 'splunk_ta_aws_sqs_queue_names': Unexpected error "" from python handler: "No AWS Account is configured. Setup App first.". See splunkd.log for more details."&lt;BR /&gt;
I think this is due to that I did not specify my AWS access key and secrete key.&lt;BR /&gt;
My question...&lt;BR /&gt;
 1. Where is the Splunk Web to enter my account, access key and secrete key?&lt;BR /&gt;
 2. How do I configure access key and secrete key manually if I have to?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165385#M15670</guid>
      <dc:creator>cchsiang2002</dc:creator>
      <dc:date>2020-09-28T18:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165386#M15671</link>
      <description>&lt;P&gt;I got it.&lt;BR /&gt;&lt;BR /&gt;
thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 17:59:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165386#M15671</guid>
      <dc:creator>cchsiang2002</dc:creator>
      <dc:date>2014-12-28T17:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165387#M15672</link>
      <description>&lt;P&gt;hi. i just converted all your 'answers' into comments. in the future, please don't use the 'answer' field to ask questions or comment. &lt;/P&gt;</description>
      <pubDate>Sun, 28 Dec 2014 18:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165387#M15672</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2014-12-28T18:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165388#M15673</link>
      <description>&lt;P&gt;I am getting the same problem.  I tried using a root access key just to confirm its not permissions&lt;/P&gt;

&lt;P&gt;Failed to fetch data: In handler 'splunk_ta_aws_sqs_queue_names': Unexpected error "" from python handler: "'error' object has no attribute 'status'". See splunkd.log for more details.&lt;/P&gt;

&lt;P&gt;Any advise?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165388#M15673</guid>
      <dc:creator>clifforg</dc:creator>
      <dc:date>2020-09-28T19:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165389#M15674</link>
      <description>&lt;P&gt;I would turn on DEBUG logging&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 17:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165389#M15674</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-04-14T17:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165390#M15675</link>
      <description>&lt;P&gt;Doesn't appear to be that great - from splunkd.log&lt;/P&gt;

&lt;P&gt;04-14-2015 13:21:12.643 -0400 ERROR AdminManagerExternal - Stack trace from python handler:\nTraceback (most recent call last):\n  File "/opt/splunk/lib/python2.7/site-packages/splunk/admin.py", line 70, in init\n    hand.execute(info)\n  File "/opt/splunk/lib/python2.7/site-packages/splunk/admin.py", line 527, in execute\n    if self.requestedAction == ACTION_LIST:     self.handleList(confInfo)\n  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunk_ta_aws_sqs_queue_names_handler.py", line 26, in wrapper\n    result = func(*args, **kwargs)\n  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunk_ta_aws_sqs_queue_names_handler.py", line 73, in handleList\n    type(e).&lt;STRONG&gt;name&lt;/STRONG&gt;, e.status, e.reason, e.error_code, e.error_message))\nAttributeError: 'error' object has no attribute 'status'\n&lt;BR /&gt;
04-14-2015 13:21:12.643 -0400 ERROR AdminManagerExternal - Unexpected error "" from python handler: "'error' object has no attribute 'status'".  See splunkd.log for more details.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165390#M15675</guid>
      <dc:creator>clifforg</dc:creator>
      <dc:date>2020-09-28T19:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165391#M15676</link>
      <description>&lt;P&gt;I suspect that you've turned on Splunk Enterprise debug or something? I was actually referring to the Add-ons' debug logging, accessed via Manage Apps -&amp;gt; setup. The general troubleshooting section for Add-ons goes over what to look for: &lt;A href="http://docs.splunk.com/Documentation/AddOns/released/Overview/Troubleshootadd-ons"&gt;http://docs.splunk.com/Documentation/AddOns/released/Overview/Troubleshootadd-ons&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 18:05:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165391#M15676</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-04-14T18:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk app for AWS" does not allow Cloudtrail Data Input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165392#M15677</link>
      <description>&lt;P&gt;I did it through the Apps--&amp;gt;Setup - but I was still looking in the splunkd.log for the information.&lt;/P&gt;

&lt;P&gt;I ran the query per the link you sent&lt;/P&gt;

&lt;P&gt;index = _internal source=&lt;EM&gt;aws&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;and I see DEBUG entries - but not errors.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 18:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/quot-Splunk-app-for-AWS-quot-does-not-allow-Cloudtrail-Data/m-p/165392#M15677</guid>
      <dc:creator>clifforg</dc:creator>
      <dc:date>2015-04-14T18:25:16Z</dc:date>
    </item>
  </channel>
</rss>

