<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Import  specific data from S3 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Import-specific-data-from-S3/m-p/507394#M2418</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am trying to import a specific account data from AWS S3&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have configured SQS to import the full data from the same S3&amp;nbsp; and it works properly&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have defined the inputs as below&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the account path in AWS is&amp;nbsp;&lt;A href="https://s3.console.aws.amazon.com/s3/home?region=eu-west-1" target="_blank" rel="noopener"&gt;Amazon S3&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/buckets/amdocsinfosectrail/?region=eu-west-1&amp;amp;tab=overview" target="_blank" rel="noopener"&gt;amdocsinfosectrail&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/buckets/amdocsinfosectrail/AWSLogs/?region=eu-west-1&amp;amp;tab=overview" target="_blank" rel="noopener"&gt;AWSLogs&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/buckets/amdocsinfosectrail/AWSLogs/o-kgohve3tjc/?region=eu-west-1&amp;amp;tab=overview" target="_blank" rel="noopener"&gt;o-kgohve3tjc&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/#" target="_blank" rel="noopener"&gt;001519100451&lt;/A&gt;&lt;/P&gt;&lt;P&gt;what I am missing&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;the logs are not created with the key_name&amp;nbsp;&lt;/P&gt;&lt;P&gt;once I remove the filter I see that the&amp;nbsp;/opt/splunk/var/lib/splunk/modinputs/aws_s3/amdocsinfosectrail_001519100451.index.v3.ckpt is getting the list of files&amp;nbsp;&lt;/P&gt;&lt;P&gt;what I am missing&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;[aws_s3://amdocsinfosectrail_001519100451]&lt;BR /&gt;aws_account = IS account&lt;BR /&gt;bucket_name = amdocsinfosectrail&lt;BR /&gt;character_set = auto&lt;BR /&gt;ct_blacklist = ^$&lt;BR /&gt;host_name = s3.amazonaws.com&lt;BR /&gt;index = test&lt;BR /&gt;initial_scan_datetime = -180d&lt;BR /&gt;interval = 30&lt;BR /&gt;is_secure = True&lt;BR /&gt;max_items = 100000&lt;BR /&gt;max_retries = 3&lt;BR /&gt;recursion_depth = -1&lt;BR /&gt;sourcetype = aws:s3&lt;BR /&gt;disabled = 0&lt;BR /&gt;key_name = AWSLogs/o-kgohve3tjc/001519100451/*&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jul 2020 09:14:30 GMT</pubDate>
    <dc:creator>rayar</dc:creator>
    <dc:date>2020-07-05T09:14:30Z</dc:date>
    <item>
      <title>Import  specific data from S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Import-specific-data-from-S3/m-p/507394#M2418</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am trying to import a specific account data from AWS S3&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have configured SQS to import the full data from the same S3&amp;nbsp; and it works properly&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have defined the inputs as below&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the account path in AWS is&amp;nbsp;&lt;A href="https://s3.console.aws.amazon.com/s3/home?region=eu-west-1" target="_blank" rel="noopener"&gt;Amazon S3&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/buckets/amdocsinfosectrail/?region=eu-west-1&amp;amp;tab=overview" target="_blank" rel="noopener"&gt;amdocsinfosectrail&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/buckets/amdocsinfosectrail/AWSLogs/?region=eu-west-1&amp;amp;tab=overview" target="_blank" rel="noopener"&gt;AWSLogs&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/buckets/amdocsinfosectrail/AWSLogs/o-kgohve3tjc/?region=eu-west-1&amp;amp;tab=overview" target="_blank" rel="noopener"&gt;o-kgohve3tjc&lt;/A&gt;&lt;SPAN class="breadcrumb-path-separator ng-scope"&gt;/&lt;/SPAN&gt;&lt;A href="https://s3.console.aws.amazon.com/s3/#" target="_blank" rel="noopener"&gt;001519100451&lt;/A&gt;&lt;/P&gt;&lt;P&gt;what I am missing&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;the logs are not created with the key_name&amp;nbsp;&lt;/P&gt;&lt;P&gt;once I remove the filter I see that the&amp;nbsp;/opt/splunk/var/lib/splunk/modinputs/aws_s3/amdocsinfosectrail_001519100451.index.v3.ckpt is getting the list of files&amp;nbsp;&lt;/P&gt;&lt;P&gt;what I am missing&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;[aws_s3://amdocsinfosectrail_001519100451]&lt;BR /&gt;aws_account = IS account&lt;BR /&gt;bucket_name = amdocsinfosectrail&lt;BR /&gt;character_set = auto&lt;BR /&gt;ct_blacklist = ^$&lt;BR /&gt;host_name = s3.amazonaws.com&lt;BR /&gt;index = test&lt;BR /&gt;initial_scan_datetime = -180d&lt;BR /&gt;interval = 30&lt;BR /&gt;is_secure = True&lt;BR /&gt;max_items = 100000&lt;BR /&gt;max_retries = 3&lt;BR /&gt;recursion_depth = -1&lt;BR /&gt;sourcetype = aws:s3&lt;BR /&gt;disabled = 0&lt;BR /&gt;key_name = AWSLogs/o-kgohve3tjc/001519100451/*&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 09:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Import-specific-data-from-S3/m-p/507394#M2418</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-07-05T09:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Import  specific data from S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Import-specific-data-from-S3/m-p/563815#M9740</link>
      <description>&lt;P&gt;Did you every get a solution to this?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 16:57:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Import-specific-data-from-S3/m-p/563815#M9740</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2021-08-18T16:57:02Z</dc:date>
    </item>
  </channel>
</rss>

