<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error Ingest Data AWS Cloudtrail &amp;quot;error=Traceback (most recent call last):&amp;quot; in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747809#M29527</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269896"&gt;@zksvc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the inputs are polling AWS Cloudwatch too frequently, which is giving your Rate Limit exception.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have just set this up then it will be trying to pull logs back from whatever the&amp;nbsp;&lt;SPAN&gt;only_after date you set was (see&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/&lt;/A&gt;&amp;nbsp;for input config descriptions)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you left this field blank then I believe it tries to load all the events in the Cloudwatch logs group in AWS. Ultimately it looks like its repeatedly querying CW Logs to get more logs which is why it is hitting the rate limit. The number of polls to CW Logs will reduce once it has caught up to the current date. It might be worth enabling one at a time to allow them to catch up gradually.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you do not need the historic data then I would suggest cloning the inputs and setting the&amp;nbsp;&lt;SPAN&gt;only_after date to a recent date and then deleting the old input. I dont think it is possible to change the&amp;nbsp;only_after once created because of how the checkpoint of the current date/time is recorded, but I may be wrong here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jun 2025 11:09:25 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-06-11T11:09:25Z</dc:date>
    <item>
      <title>Error Ingest Data AWS Cloudtrail "error=Traceback (most recent call last):"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747808#M29526</link>
      <description>&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I encountered an error while ingesting sourcetype=aws:cloudtrails in AWS Apps. I attempted to ingest data from the following sources: aws:waflogs, aws:network-firewall-log, aws:cloudtrails, aws:securityhub-log-group. However, upon checking, only aws:waflogs and aws:network-firewall-log were ingested. Attached below are the errors from the logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zksvc_0-1749639515584.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39343i78CABA4448C46815/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zksvc_0-1749639515584.png" alt="zksvc_0-1749639515584.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also i screenshot inputs config from the apps side here :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zksvc_2-1749639584109.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39345i602405CA493B628E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zksvc_2-1749639584109.png" alt="zksvc_2-1749639584109.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Last i show you the proof if i only received that 2 sourctypes here :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zksvc_3-1749639668960.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39346i25F6B00C73350D11/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zksvc_3-1749639668960.png" alt="zksvc_3-1749639668960.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have any experience from this issue, please give me the answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Danke,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zake&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 11:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747808#M29526</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2025-06-11T11:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error Ingest Data AWS Cloudtrail "error=Traceback (most recent call last):"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747809#M29527</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269896"&gt;@zksvc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the inputs are polling AWS Cloudwatch too frequently, which is giving your Rate Limit exception.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have just set this up then it will be trying to pull logs back from whatever the&amp;nbsp;&lt;SPAN&gt;only_after date you set was (see&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/&lt;/A&gt;&amp;nbsp;for input config descriptions)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you left this field blank then I believe it tries to load all the events in the Cloudwatch logs group in AWS. Ultimately it looks like its repeatedly querying CW Logs to get more logs which is why it is hitting the rate limit. The number of polls to CW Logs will reduce once it has caught up to the current date. It might be worth enabling one at a time to allow them to catch up gradually.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you do not need the historic data then I would suggest cloning the inputs and setting the&amp;nbsp;&lt;SPAN&gt;only_after date to a recent date and then deleting the old input. I dont think it is possible to change the&amp;nbsp;only_after once created because of how the checkpoint of the current date/time is recorded, but I may be wrong here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 11:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747809#M29527</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-11T11:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Error Ingest Data AWS Cloudtrail "error=Traceback (most recent call last):"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747810#M29528</link>
      <description>&lt;P&gt;Thanks for your reply,&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;I will try to change the interval time to 600 seconds first.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 11:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747810#M29528</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2025-06-11T11:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Error Ingest Data AWS Cloudtrail "error=Traceback (most recent call last):"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747858#M29529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; I have changed the interval to 600 seconds, but the data is still not available. Is there any other solution that you know?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 01:51:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Error-Ingest-Data-AWS-Cloudtrail-quot-error-Traceback-most/m-p/747858#M29529</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2025-06-12T01:51:41Z</dc:date>
    </item>
  </channel>
</rss>

