<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275158#M32119</link>
    <description>&lt;P&gt;I'm seeing the same behavior with Splunk running on Windows 7&lt;/P&gt;</description>
    <pubDate>Mon, 28 Dec 2015 20:30:37 GMT</pubDate>
    <dc:creator>kyleguillot</dc:creator>
    <dc:date>2015-12-28T20:30:37Z</dc:date>
    <item>
      <title>Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275147#M32108</link>
      <description>&lt;P&gt;I am pulling data from 30-40 log groups from 3 different regions using the Splunk Add-on for AWS.  I am having an issue where after about 10-15 minutes, I stop receiving the most up to date events from half of my log groups.  I receive data initially just fine from all log groups, but it seems after it pulls the most recent data at the time it doesn't check again for more data.  The delay and interval settings are set to the default and I've confirmed that the most current events are being received by the Cloudwatch logs service.  My only clue seems to be this event in the Splunk internal logs that occurs for my log groups with this issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-12-08 17:52:22,328 INFO pid=7026 tid=Thread-298 file=aws_cloudwatch_logs.py:_do_was_job_func:130 | Previous job of the same task still running. Exit current job. region=us-west-2, log_group=syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This event seems to occur indefinitely every 10 minutes and Splunk never pulls more data from the log group again.  &lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 23:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275147#M32108</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2015-12-08T23:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275148#M32109</link>
      <description>&lt;P&gt;What version of the add-on are you running?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 01:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275148#M32109</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2015-12-09T01:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275149#M32110</link>
      <description>&lt;P&gt;version 2.0.1&lt;/P&gt;

&lt;P&gt;Also one thing I forgot to specify, when I restart the splunk server, it follows the same behavior as described above, pulls all data  from all logs again up to most recent, then stops and shows that message.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 15:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275149#M32110</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2015-12-09T15:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275150#M32111</link>
      <description>&lt;P&gt;What OS is being used to host Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 17:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275150#M32111</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2015-12-09T17:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275151#M32112</link>
      <description>&lt;P&gt;Ubuntu 14.04&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 17:50:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275151#M32112</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2015-12-09T17:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275152#M32113</link>
      <description>&lt;P&gt;Ubuntu's dash shell returns a different SIGTERM than bash, resulting in orphaned input processes. This was meant to have been resolved in TA version 2.0.1 (which is why rpille asked which version). At first glance, it appears this condition is being detected and partially handled (additional processes aren't spawned when orphaned processes exist, yet the orphaned process is not terminated). I'll file a new bug for this and explore workarounds.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 18:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275152#M32113</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2015-12-09T18:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275153#M32114</link>
      <description>&lt;P&gt;Hi @nickpayze, can you try adding a &lt;CODE&gt;start_by_shell=false&lt;/CODE&gt; to the &lt;CODE&gt;[aws_cloudwatch_logs]&lt;/CODE&gt;configuration in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and re-starting Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 18:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275153#M32114</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2015-12-09T18:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275154#M32115</link>
      <description>&lt;P&gt;I've added the setting and it does get rid of the bash process that runs alongside the python process for aws_cloudwatch_logs.py . I am still getting the same behavior as before though. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275154#M32115</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2020-09-29T08:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275155#M32116</link>
      <description>&lt;P&gt;Will I have to wait until this issue is resolved in the next version of the aws add-on?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2015 19:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275155#M32116</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2015-12-10T19:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275156#M32117</link>
      <description>&lt;P&gt;Would you turn on the debug log and double check if you can find log message "Start to describe streams &lt;EM&gt;**"  and "Job ended.  region *&lt;/EM&gt;*" for each interval? The log group name should be print out in those message.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 14:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275156#M32117</guid>
      <dc:creator>azhang_splunk</dc:creator>
      <dc:date>2015-12-11T14:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275157#M32118</link>
      <description>&lt;P&gt;I do not see any "Job ended" messages for any of my log groups.  &lt;/P&gt;

&lt;P&gt;I see many "Start to describe streams" messages for the log groups I am still receiving events on (every few seconds) and the " Previous job of the same task still running" message running every 10 minutes for the log groups I stopped receiving events on.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2015 16:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275157#M32118</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2015-12-14T16:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275158#M32119</link>
      <description>&lt;P&gt;I'm seeing the same behavior with Splunk running on Windows 7&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 20:30:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275158#M32119</guid>
      <dc:creator>kyleguillot</dc:creator>
      <dc:date>2015-12-28T20:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275159#M32120</link>
      <description>&lt;P&gt;I found a Throttling exception ERROR in the internal logs that may be another clue, could this be the culprit?:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-12-10 16:21:51,357 ERROR pid=24928 tid=Thread-23 file=util.py:describe_cloudwatch_log_streams:118 | Failure in describing cloudwatch logs streams due to throttling exception for log_group=kern.log, sleep=5.96629281236, reason=Traceback (most recent call last):
File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudwatch_logs_resources/util.py", line 108, in describe_cloudwatch_log_streams
    group_name, next_token=buf["nextToken"])
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/boto/logs/layer1.py", line 308, in describe_log_streams
    body=json.dumps(params))
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/boto/logs/layer1.py", line 576, in make_request
    body=json_body)
JSONResponseError: JSONResponseError: 400 Bad Request
{u'message': u'Rate exceeded', u'__type': u'ThrottlingException'}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Jan 2016 16:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275159#M32120</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2016-01-12T16:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275160#M32121</link>
      <description>&lt;P&gt;The latest amazon add-on version I updated to (3.0.0) has fixed the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 17:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275160#M32121</guid>
      <dc:creator>nickpayze</dc:creator>
      <dc:date>2016-01-29T17:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275161#M32122</link>
      <description>&lt;P&gt;For what it's worth, @nickpayze, I'm seeing this on 3.0.0. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Same throttling exception that you saw&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 04:35:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275161#M32122</guid>
      <dc:creator>wsh</dc:creator>
      <dc:date>2016-04-12T04:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275162#M32123</link>
      <description>&lt;P&gt;Also seeing this issue on 4.0.0&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 21:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275162#M32123</guid>
      <dc:creator>gsumner</dc:creator>
      <dc:date>2016-08-02T21:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275163#M32124</link>
      <description>&lt;P&gt;We have this same issue running latest 4.1.0 version. It seems to try to run describe_log_stream against all log_groups at the same time which is probably causing the throttling. This is especially an issue when you have a large set of log_groups. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:16:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275163#M32124</guid>
      <dc:creator>lcasey001</dc:creator>
      <dc:date>2020-09-29T11:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275164#M32125</link>
      <description>&lt;P&gt;Can confirm, throttling errors with version 4.1.0 and only 11 cloudwatch logs logstreams.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Failure in describing cloudwatch logs streams due to throttling exception for log_group=, sleep=5.98632069244, reason=Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/cloudwatch_logs_mod/aws_cloudwatch_logs_data_loader.py", line 64, in describe_cloudwatch_log_streams
    group_name, next_token=buf["nextToken"])
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/boto/logs/layer1.py", line 308, in describe_log_streams
    body=json.dumps(params))
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/boto/logs/layer1.py", line 576, in make_request
    body=json_body)
JSONResponseError: JSONResponseError: 400 Bad Request
{u'__type': u'ThrottlingException', u'message': u'Rate exceeded'}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 05 Oct 2016 04:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275164#M32125</guid>
      <dc:creator>henrikhuitti</dc:creator>
      <dc:date>2016-10-05T04:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275165#M32126</link>
      <description>&lt;P&gt;I am also seeing the same throttling alerts in 4.1.1&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 18:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275165#M32126</guid>
      <dc:creator>amiller100</dc:creator>
      <dc:date>2016-10-24T18:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Amazon Web Services: Why do I stop receiving events from some of my Cloudwatch log log-groups?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275166#M32127</link>
      <description>&lt;P&gt;We resolved this issue with changing from direct cloudwatch logs to Kinesis, please check &lt;A href="http://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/Subscriptions.html"&gt;http://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/Subscriptions.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We also got answer from AWS:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;. Instead you should use the Kinesis subscription integration that Splunk apparently provides, but does not use by default. The default Splunk integration only works for very small customers. You should reach out to Splunk for support if needed on how to use Splunk with CloudWatch Logs.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 25 Oct 2016 05:13:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Amazon-Web-Services-Why-do-I-stop-receiving/m-p/275166#M32127</guid>
      <dc:creator>henrikhuitti</dc:creator>
      <dc:date>2016-10-25T05:13:19Z</dc:date>
    </item>
  </channel>
</rss>

