<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213068#M22909</link>
    <description>&lt;P&gt;Thanks again for the help.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Created new S3 bucket using AWS defaults, still no change in result.&lt;/LI&gt;
&lt;LI&gt;Region is N.Virginia - us-east-1 - confirmed that is the same.&lt;/LI&gt;
&lt;LI&gt;Noted about inputs.conf, thank you.&lt;/LI&gt;
&lt;LI&gt;I only tried CloudTrail this time but result is the same, SQS field in Splunk Data Input for CloudTrail is blank.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Would it be too much to ask to see your screenshots?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2015 16:20:26 GMT</pubDate>
    <dc:creator>asbetsplunk</dc:creator>
    <dc:date>2015-09-11T16:20:26Z</dc:date>
    <item>
      <title>Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213064#M22905</link>
      <description>&lt;P&gt;I have followed the instructions for setting up a standalone Splunk Enterprise server on AWS.&lt;/P&gt;

&lt;P&gt;However, when I get to the data inputs section nothing is displaying for the SQS queues. &lt;/P&gt;

&lt;P&gt;I took screenshots of the whole process - ran into all kinds of crazy issues:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.dropbox.com/s/toy9q4h0nlfux94/Splunk.AWS.Install_Redacted.pdf"&gt;https://www.dropbox.com/s/toy9q4h0nlfux94/Splunk.AWS.Install_Redacted.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Can someone please show me where I messed up?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 07:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213064#M22905</guid>
      <dc:creator>asbetsplunk</dc:creator>
      <dc:date>2015-09-03T07:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213065#M22906</link>
      <description>&lt;P&gt;Hi there, &lt;/P&gt;

&lt;P&gt;I see you created all the policies in your AWS console, but when you created the user account, did you attach those policies to it? There are various ways you can accomplish this in AWS. A simple way to do it is to create a Group and then attach all the policies to that group, then put your Splunk user in that group. &lt;/P&gt;

&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 22:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213065#M22906</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2015-09-03T22:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213066#M22907</link>
      <description>&lt;P&gt;Thank you very much for the reply but unfortunately no luck. I can't believe that I forgot to add the policies to the account though!&lt;/P&gt;

&lt;P&gt;Anyway, I gave it another try - here are screenshots of the steps:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.dropbox.com/s/0sn6907y9isbjmr/splunk.aws.troubleshooting_Redacted.pdf"&gt;https://www.dropbox.com/s/0sn6907y9isbjmr/splunk.aws.troubleshooting_Redacted.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I also tried some things at the command line like manually adding the AWS ID but no change.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 06:20:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213066#M22907</guid>
      <dc:creator>asbetsplunk</dc:creator>
      <dc:date>2015-09-04T06:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213067#M22908</link>
      <description>&lt;P&gt;Some ideas:&lt;/P&gt;

&lt;P&gt;When you were on the CloudTrail configuration screen and it asked you if you wanted to create a new S3 bucket, try saying Yes and allowing AWS to define the correct permissions for that bucket for you automatically. There may be something missing there. If you don't want to do that, be sure to follow the AWS documentation for how to get the permissions correct here. (&lt;A href="http://docs.aws.amazon.com/awscloudtrail/latest/userguide/create-s3-bucket-policy-for-cloudtrail.html"&gt;http://docs.aws.amazon.com/awscloudtrail/latest/userguide/create-s3-bucket-policy-for-cloudtrail.html&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;Just checking, since you have your region redacted in your AWS console screenshots -- did you make sure the region you are using here matches the one you used in AWS?&lt;/P&gt;

&lt;P&gt;When you try to manage settings in the inputs.conf file, please be sure to copy default/inputs.conf to local and edit there to save yourself future pain. Not relevant to your current troubleshooting, just a best practice.&lt;/P&gt;

&lt;P&gt;Also in the conf file, it looks like you used your key ID for the aws_account parameter, but it expects the account friendly name there. Could account for the error.&lt;/P&gt;

&lt;P&gt;Be sure to follow the documentation to add all the other parameters that you need: &lt;A href="http://docs.splunk.com/Documentation/AddOns/released/AWS/ConfigureInputs#CloudTrail_inputs"&gt;http://docs.splunk.com/Documentation/AddOns/released/AWS/ConfigureInputs#CloudTrail_inputs&lt;/A&gt;  The default file you were editing doesn't include them all. Note that for the queue name, it just expects the final segment of the full queue URL. For example, if your SQS queue URL is &lt;A href="http://sqs.us-east-1.amazonaws.com/123456789012/testQueue"&gt;http://sqs.us-east-1.amazonaws.com/123456789012/testQueue&lt;/A&gt;, then your SQS queue name is testQueue.&lt;/P&gt;

&lt;P&gt;I just re-tested the steps with a new user that I put in a new group and attached ONLY the CloudTrail policy from the documentation to that group, and it is working for me. I suspect there is something awry with your policies, probably the one on the S3 bucket.&lt;/P&gt;

&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2015 01:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213067#M22908</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2015-09-05T01:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213068#M22909</link>
      <description>&lt;P&gt;Thanks again for the help.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Created new S3 bucket using AWS defaults, still no change in result.&lt;/LI&gt;
&lt;LI&gt;Region is N.Virginia - us-east-1 - confirmed that is the same.&lt;/LI&gt;
&lt;LI&gt;Noted about inputs.conf, thank you.&lt;/LI&gt;
&lt;LI&gt;I only tried CloudTrail this time but result is the same, SQS field in Splunk Data Input for CloudTrail is blank.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Would it be too much to ask to see your screenshots?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 16:20:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213068#M22909</guid>
      <dc:creator>asbetsplunk</dc:creator>
      <dc:date>2015-09-11T16:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213069#M22910</link>
      <description>&lt;P&gt;Perhaps you've found a bug, or perhaps you are still encountering a permissions issue in AWS, somehow. Let's try to eliminate the latter. &lt;/P&gt;

&lt;P&gt;Try creating a local/inputs.conf with your CloudTrail input information. &lt;/P&gt;

&lt;P&gt;First, in Splunk Web, go back to the setup page and set CloudTrail logging to DEBUG. &lt;/P&gt;

&lt;P&gt;Then, create your local/inputs.conf file:&lt;/P&gt;

&lt;P&gt;[aws_cloudtrail://somename]&lt;BR /&gt;
aws_account = the friendly name of your aws account&lt;BR /&gt;
aws_region = us-east-1&lt;BR /&gt;
sqs_queue = the last segment of the full queue url&lt;/P&gt;

&lt;P&gt;Save the file, then restart Splunk Enterprise. &lt;/P&gt;

&lt;P&gt;Search for sourcetype=aws:cloudtrail&lt;/P&gt;

&lt;P&gt;If you don't see events, search index = _internal source=&lt;EM&gt;aws&lt;/EM&gt; and look for interesting errors. &lt;/P&gt;

&lt;P&gt;More troubleshooting tips here: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/Overview/Troubleshootadd-ons" target="_blank"&gt;http://docs.splunk.com/Documentation/AddOns/latest/Overview/Troubleshootadd-ons&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:15:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213069#M22910</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2020-09-29T07:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213070#M22911</link>
      <description>&lt;P&gt;Hi again, asbetsplunk. We've released a new version of this add-on (version 2.0.0) with a lot of bugfixes. You might try running that version instead to see if the issue persists. Please let us know if you are still having problems with it! &lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 02:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213070#M22911</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2015-09-25T02:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services - Nothing Showing for Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213071#M22912</link>
      <description>&lt;P&gt;Hi, Do you have some other service to get data from the same SQS ??  Message in a SQS can only be taken one time, if multiple service subscribe messages from the same SQS, only one of them can get the data.&lt;/P&gt;

&lt;P&gt;If you do have multiple services to consume these messages, I suggest you create separate SQS to describe data from a fixed SNS as data source and then create individual data inputs for individual SQS, not to share SQS&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 03:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Nothing-Showing-for-Data/m-p/213071#M22912</guid>
      <dc:creator>chwang_splunk</dc:creator>
      <dc:date>2015-09-25T03:15:51Z</dc:date>
    </item>
  </channel>
</rss>

