<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303005#M36109</link>
    <description>&lt;P&gt;You need to install the Splunk_TA_aws.&lt;BR /&gt;
The app just does the vis and saved searches. The TA collects the actual data from the AWS webservices.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:02:00 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2020-09-29T17:02:00Z</dc:date>
    <item>
      <title>Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303001#M36105</link>
      <description>&lt;P&gt;I am using Splunk Free Enterprise, and have had a ton of difficulty in getting data from AWS Cloudwatch into the Splunk Add-On for Amazon Web Services. In addition, the Splunk App for AWS simply doesn't work with the add-on. I can see events in the add-on for the AWS/EC2 namespace, and yet the app has 0 for everything. My inputs are going to the "main" index, not anything special. And I am only collecting from the "InstanceId" dimension for EC2 (as I saw a post earlier saying the others wouldn't work)&lt;/P&gt;

&lt;P&gt;So, do they actually work in the free enterprise version? Is there something I need to set up to help the two parts communicate? &lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 19:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303001#M36105</guid>
      <dc:creator>mvdp</dc:creator>
      <dc:date>2017-11-23T19:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303002#M36106</link>
      <description>&lt;P&gt;Yes.  Those are totally free apps.  They would only not work on free if some feature depended on either license stacking (definitely not) or on clustering (surely not).&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 01:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303002#M36106</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-11-27T01:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303003#M36107</link>
      <description>&lt;P&gt;I'm reading that Q as .. yes the apps are free .. but do they work on the limited free version of Splunk ? &lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 02:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303003#M36107</guid>
      <dc:creator>Esky73</dc:creator>
      <dc:date>2017-11-27T02:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303004#M36108</link>
      <description>&lt;P&gt;Thanks for the comments Woodcock and Esky73. I have gone through the documentation and tried a lot of different things to get the data from the add-on into the app and nothing has worked. &lt;/P&gt;

&lt;P&gt;Do you know if I have to be collecting all of the Cloudwatch data, not just the EC2 data for the app to work? I would have thought that I could see the EC2 data in the AWS App without having to get the ELB, billing. RDS etc. data. Or is there something special that needs to be configured and is undocumented?&lt;/P&gt;

&lt;P&gt;On the configuration page in the App for AWS, I have no options to do anything other than a few checkboxes to enable warning messages and a button to select billing tags. &lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 13:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303004#M36108</guid>
      <dc:creator>mvdp</dc:creator>
      <dc:date>2017-11-27T13:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303005#M36109</link>
      <description>&lt;P&gt;You need to install the Splunk_TA_aws.&lt;BR /&gt;
The app just does the vis and saved searches. The TA collects the actual data from the AWS webservices.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303005#M36109</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-09-29T17:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303006#M36110</link>
      <description>&lt;P&gt;Yes, I have both the Splunk add-on for AWS (where I can see events for the EC2 data) and the Splunk App for AWS (which won't communicate with the add-on to get the data to display it). &lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 13:59:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303006#M36110</guid>
      <dc:creator>mvdp</dc:creator>
      <dc:date>2017-11-27T13:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303007#M36111</link>
      <description>&lt;P&gt;In the most recent version of the AWS app 5.1.0 the app no longer 'communicates' with the TA like it did in previous versions. Instead you perform all of the input config in the TA, and switch to the app to view it. As an aside, if your using AWS config - the TA no longer generates a config snapshot for you - you will have to trigger the API to do this for you, and there is no mention of this in the documentation (I have raised this with support!).&lt;/P&gt;

&lt;P&gt;I am not sure what data you would be trying to collect, but the bulk of the useful information comes from the Config and cloud trail services. The app uses those historical audit and activity sources to populate most of the dashboards. Its not talking directly to the ec2 endpoints to get performance or machine data data.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303007#M36111</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-11-27T14:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303008#M36112</link>
      <description>&lt;P&gt;Oh - also, have you enabled the summary saved searches on the TA - these take your TA configured inputs and write them into a summary index. The app then uses the results from the summary index to pass to the other saved searches which generate the data.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303008#M36112</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-11-27T14:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303009#M36113</link>
      <description>&lt;P&gt;Thanks, that's good to know! I was only collecting EC2 metrics from AWS cloudwatch, so maybe that's the problem. I will try collecting from Config and Cloudtrail too and see what happens. I have the  "Addon Metadata - Summarize AWS Inputs" enabled. Is that what you mean by the summary saved search? (I'm rather new to Splunk)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303009#M36113</guid>
      <dc:creator>mvdp</dc:creator>
      <dc:date>2017-11-27T14:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303010#M36114</link>
      <description>&lt;P&gt;thats the one!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:18:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303010#M36114</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-11-27T14:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Do the Splunk App for AWS and Splunk Add-On for Amazon Web Services work with Splunk free?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303011#M36115</link>
      <description>&lt;P&gt;Ok, thanks for your help! I did a quick search on the summary index and it appears to be working so I'll try adding the other inputs and go from there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Do-the-Splunk-App-for-AWS-and-Splunk-Add-On-for-Amazon-Web/m-p/303011#M36115</guid>
      <dc:creator>mvdp</dc:creator>
      <dc:date>2017-11-27T14:20:15Z</dc:date>
    </item>
  </channel>
</rss>

