<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to forward the data from AWS S3 to Splunk Enterprise? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669424#M17902</link>
    <description>&lt;P&gt;I have installed a free version of Splunk Enterprise 9.1 in my local system. I would need few logs files from my S3 bucket to be sent to Splunk.&lt;/P&gt;&lt;P&gt;I have setup up the Splunk Add-on for AWS. In the app, under configuration, created an account with access ID and secret access key. Then created an input by specifying the account name, bucket name and indexing details.&lt;/P&gt;&lt;P class=""&gt;After creating the input, when I search my index and sourcetype, I could not find the logs from S3. I have waited for more than half an hour, then tried again but no luck.&lt;/P&gt;&lt;P class=""&gt;As this is the first time I am trying the setup with AWS add-on, I am not sure whether the issue is happening. Could anyone please help me on this?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2023 07:43:34 GMT</pubDate>
    <dc:creator>akarivaratharaj</dc:creator>
    <dc:date>2023-11-22T07:43:34Z</dc:date>
    <item>
      <title>How to forward the data from AWS S3 to Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669424#M17902</link>
      <description>&lt;P&gt;I have installed a free version of Splunk Enterprise 9.1 in my local system. I would need few logs files from my S3 bucket to be sent to Splunk.&lt;/P&gt;&lt;P&gt;I have setup up the Splunk Add-on for AWS. In the app, under configuration, created an account with access ID and secret access key. Then created an input by specifying the account name, bucket name and indexing details.&lt;/P&gt;&lt;P class=""&gt;After creating the input, when I search my index and sourcetype, I could not find the logs from S3. I have waited for more than half an hour, then tried again but no luck.&lt;/P&gt;&lt;P class=""&gt;As this is the first time I am trying the setup with AWS add-on, I am not sure whether the issue is happening. Could anyone please help me on this?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 07:43:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669424#M17902</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2023-11-22T07:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward the data from AWS S3 to Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669430#M17903</link>
      <description>&lt;P&gt;Please check the aws s3 logs in the splunk end it may be due to permission issue from aws end. Once you go through the logs you will get clear visibility.&amp;nbsp; the logs will be under /opt/splunk/var/log/splunk and serach for aws.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 08:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669430#M17903</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2023-11-22T08:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward the data from AWS S3 to Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669442#M17905</link>
      <description>&lt;P&gt;Yes, there was some error with endpoint. I have checked the error via below query&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=aws:s3:log ERROR&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 22 Nov 2023 10:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669442#M17905</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2023-11-22T10:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward the data from AWS S3 to Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669443#M17906</link>
      <description>&lt;P&gt;I am curious to know about a couple of things related to fetching S3 logs.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is there any limitation in the number of inputs which we create in the AWS add-on?&lt;/LI&gt;&lt;LI&gt;Is there any limitation on indexes on which we log the S3 data?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 22 Nov 2023 10:11:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-forward-the-data-from-AWS-S3-to-Splunk-Enterprise/m-p/669443#M17906</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2023-11-22T10:11:15Z</dc:date>
    </item>
  </channel>
</rss>

