<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloud splunk-S3 bucket Failed to collect s3 data in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Cloud-splunk-S3-bucket-Failed-to-collect-s3-data/m-p/277105#M21828</link>
    <description>&lt;P&gt;We are having this same issue. Was anyone able to make progress on this.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 17:16:57 GMT</pubDate>
    <dc:creator>ejenson_splunk</dc:creator>
    <dc:date>2017-01-11T17:16:57Z</dc:date>
    <item>
      <title>Cloud splunk-S3 bucket Failed to collect s3 data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Cloud-splunk-S3-bucket-Failed-to-collect-s3-data/m-p/277104#M21827</link>
      <description>&lt;P&gt;Hi all , &lt;BR /&gt;
I have configured my splunk- aws add on and aws app  . But I am getting the following error in /opt/splunk/var/log/splunk/splunk_ta_aws_s3_main.log -&lt;/P&gt;

&lt;P&gt;ERROR pid=16834 tid=MainThread file=aws_s3.py:run:132 | Failed to collect s3 data, error=Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_s3.py", line 129, in run&lt;BR /&gt;
    _do_run()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_s3.py", line 100, in _do_run&lt;BR /&gt;
    asconfig.AWSS3Conf, "aws_s3", logger)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/taaws/ta_aws_common.py", line 117, in get_configs&lt;BR /&gt;
    tasks = conf.get_tasks()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/s3_mod/aws_s3_conf.py", line 73, in get_tasks&lt;BR /&gt;
    task[asc.initial_scan_datetime])&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/s3_mod/aws_s3_conf.py", line 91, in _get_last_modified_time&lt;BR /&gt;
    scan_datetime)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/taaws/ta_aws_common.py", line 182, in parse_datetime&lt;BR /&gt;
    r = endpoint.get(time=time_str, output_time_format="%s")&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunklib/client.py", line 688, in get&lt;BR /&gt;
    **query)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunklib/binding.py", line 237, in wrapper&lt;BR /&gt;
    return request_fun(self, *args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunklib/binding.py", line 61, in new_f&lt;BR /&gt;
    val = f(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunklib/binding.py", line 582, in get&lt;BR /&gt;
    response = self.http.get(path, self._auth_headers, **query)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunklib/binding.py", line 1053, in get&lt;BR /&gt;
    return self.request(url, { 'method': "GET", 'headers': headers })&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunklib/binding.py", line 1108, in request&lt;BR /&gt;
    raise HTTPError(response)&lt;BR /&gt;
HTTPError: HTTP 400 Bad Request -- Invalid time.&lt;/P&gt;

&lt;P&gt;I have given proper bucket policies  to my s3 bucket.&lt;/P&gt;

&lt;P&gt;Any pointers will be appreciable.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Cloud-splunk-S3-bucket-Failed-to-collect-s3-data/m-p/277104#M21827</guid>
      <dc:creator>mshruti</dc:creator>
      <dc:date>2020-09-29T10:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud splunk-S3 bucket Failed to collect s3 data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Cloud-splunk-S3-bucket-Failed-to-collect-s3-data/m-p/277105#M21828</link>
      <description>&lt;P&gt;We are having this same issue. Was anyone able to make progress on this.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 17:16:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Cloud-splunk-S3-bucket-Failed-to-collect-s3-data/m-p/277105#M21828</guid>
      <dc:creator>ejenson_splunk</dc:creator>
      <dc:date>2017-01-11T17:16:57Z</dc:date>
    </item>
  </channel>
</rss>

