<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS ADD on ERROR: The search for datamodel 'CloudFront_Access_Log' failed to parse, cannot get indexes to search in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317314#M38003</link>
    <description>&lt;P&gt;It could be macro issue. Please check macro "aws-s3-index" in AWS App.  Does it have all indexes you used for CloudFront access logs? &lt;BR /&gt;
I also recommend you to upgrade to app v5.1 and add-on v4.4.  &lt;/P&gt;</description>
    <pubDate>Fri, 06 Oct 2017 08:51:37 GMT</pubDate>
    <dc:creator>pchen_splunk</dc:creator>
    <dc:date>2017-10-06T08:51:37Z</dc:date>
    <item>
      <title>AWS ADD on ERROR: The search for datamodel 'CloudFront_Access_Log' failed to parse, cannot get indexes to search</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317312#M38001</link>
      <description>&lt;P&gt;This is in regards to the Splunk ADD On for AWS:&lt;BR /&gt;
Immediately after downloading and configuring to connect to our AWS Account, I receive this error immediately when using the Splunk AWS Add-on Dashboard:&lt;/P&gt;

&lt;P&gt;The search for datamodel 'CloudFront_Access_Log' failed to parse, cannot get indexes to search &lt;/P&gt;

&lt;P&gt;Not sure if it was a permissions issue so I set the permissions on the datamodel to global but it didn't help.  I've read somewhere someone had a similar problem and was resolved by "expanding the datamodel macros".  Could this help in this case and if so, where should I go to do this?&lt;/P&gt;

&lt;P&gt;Any thoughts?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;AlexW&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317312#M38001</guid>
      <dc:creator>alexsambacanada</dc:creator>
      <dc:date>2020-09-29T14:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ADD on ERROR: The search for datamodel 'CloudFront_Access_Log' failed to parse, cannot get indexes to search</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317313#M38002</link>
      <description>&lt;P&gt;I am also seeing this error.  Were you able to figure it out?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 12:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317313#M38002</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2017-07-27T12:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ADD on ERROR: The search for datamodel 'CloudFront_Access_Log' failed to parse, cannot get indexes to search</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317314#M38003</link>
      <description>&lt;P&gt;It could be macro issue. Please check macro "aws-s3-index" in AWS App.  Does it have all indexes you used for CloudFront access logs? &lt;BR /&gt;
I also recommend you to upgrade to app v5.1 and add-on v4.4.  &lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 08:51:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/317314#M38003</guid>
      <dc:creator>pchen_splunk</dc:creator>
      <dc:date>2017-10-06T08:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ADD on ERROR: The search for datamodel 'CloudFront_Access_Log' failed to parse, cannot get indexes to search</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/522939#M63673</link>
      <description>&lt;P&gt;1. Make the app '&lt;STRONG&gt;Splunk App for AWS&lt;/STRONG&gt;' visible to all.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jawaharas_0-1601889835622.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11118i813D1EB9C611AE49/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jawaharas_0-1601889835622.png" alt="jawaharas_0-1601889835622.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;2. Also, check whether the lookup table 'cloudfront_edges' is populated. If not, run/schedule the report - '&lt;STRONG&gt;AWS Description - CloudFront Edges&lt;/STRONG&gt;&amp;nbsp;'&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 09:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-ADD-on-ERROR-The-search-for-datamodel-CloudFront-Access-Log/m-p/522939#M63673</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2020-10-05T09:28:20Z</dc:date>
    </item>
  </channel>
</rss>

