<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS Addon - SNS Signature in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/580609#M102429</link>
    <description>&lt;P&gt;After reviewing DNS queries, Proxy logs and the VPC Flow logs it turned out that only the SNS service wouldn't use the proxy.&amp;nbsp; I was able to resolve the issue by adding an SNS endpoint to the VPC/Subnet that the Splunk instance is connected to.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jan 2022 14:21:46 GMT</pubDate>
    <dc:creator>kentsaunders</dc:creator>
    <dc:date>2022-01-11T14:21:46Z</dc:date>
    <item>
      <title>AWS Addon - SNS Signature</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/579926#M102350</link>
      <description>&lt;P&gt;After updating the Splunk Add-On for AWS to 5.2.1 we are no longer receiving Cloudtrail data through a proxy server.&amp;nbsp; The message from the _internal index is "&lt;SPAN class=""&gt;message=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Warning:&lt;/SPAN&gt; &lt;SPAN class=""&gt;This&lt;/SPAN&gt; &lt;SPAN class=""&gt;message&lt;/SPAN&gt; &lt;SPAN class=""&gt;does&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;have&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;valid&lt;/SPAN&gt; &lt;SPAN class=""&gt;SNS&lt;/SPAN&gt; &lt;SPAN class=""&gt;Signature&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;urlopen&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Errno&lt;/SPAN&gt; &lt;SPAN class=""&gt;110&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;Connection&lt;/SPAN&gt; &lt;SPAN class=""&gt;timed&lt;/SPAN&gt; &lt;SPAN class=""&gt;out&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;".&amp;nbsp; If I bypass the proxy and allow outbound connections from the Splunk server on port 443 (with the proxy enabled in both the addon and server.conf) it is able to retrieve&amp;nbsp;the data.&amp;nbsp; We are running Splunk Enterprise 8.2.3.2 on a single instance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 22:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/579926#M102350</guid>
      <dc:creator>kentsaunders</dc:creator>
      <dc:date>2022-01-04T22:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Addon - SNS Signature</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/580534#M102422</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;seeing the same thing on Splunk V&lt;SPAN&gt;8.1.5 Add-on V5.2.1:&lt;/SPAN&gt;&lt;BR /&gt;2022&lt;/SPAN&gt;-01-11&lt;/SPAN&gt; &lt;SPAN class=""&gt;02:29:48&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;836&lt;/SPAN&gt; &lt;SPAN class=""&gt;level=WARNING&lt;/SPAN&gt; &lt;SPAN class=""&gt;pid=2971768&lt;/SPAN&gt; &lt;SPAN class=""&gt;tid=Thread-2&lt;/SPAN&gt; &lt;SPAN class=""&gt;logger=splunk_ta_aws.modinputs.sqs_based_s3.handler&lt;/SPAN&gt; &lt;SPAN class=""&gt;pos=handler.py:_process:299&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class=""&gt;datainput=&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;lt;foo-bar&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;start_time=1641868103&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;message_id=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;68a1a0a5-64bf-492c-a47d-96f1c3be0fb6&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;created=1641868188.579236&lt;/SPAN&gt; &lt;SPAN class=""&gt;ttl=300&lt;/SPAN&gt; &lt;SPAN class=""&gt;job_id=c3799c53-fcb9-4150-87f4-913ade22a58b&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class=""&gt;message=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Warning:&lt;/SPAN&gt; &lt;SPAN class=""&gt;This&lt;/SPAN&gt; &lt;SPAN class=""&gt;message&lt;/SPAN&gt; &lt;SPAN class=""&gt;does&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;have&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;valid&lt;/SPAN&gt; &lt;SPAN class=""&gt;SNS&lt;/SPAN&gt; &lt;SPAN class=""&gt;Signature&lt;/SPAN&gt; &lt;SPAN class=""&gt;None&lt;/SPAN&gt; &lt;SPAN class=""&gt;None&lt;/SPAN&gt; &lt;SPAN class=""&gt;doesn&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;t&lt;/SPAN&gt; &lt;SPAN class=""&gt;match&lt;/SPAN&gt; &lt;SPAN class=""&gt;required&lt;/SPAN&gt; &lt;SPAN class=""&gt;format&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class=""&gt;^&lt;A href="https://sns\" target="_blank" rel="noopener"&gt;https://sns\&lt;/A&gt;\.&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;-a-z0-9&lt;/SPAN&gt;&lt;SPAN&gt;]+&lt;/SPAN&gt;&lt;SPAN class=""&gt;\\.amazonaws\\.com&lt;/SPAN&gt;&lt;SPAN&gt;(?&lt;/SPAN&gt;&lt;SPAN class=""&gt;:\\.cn&lt;/SPAN&gt;&lt;SPAN&gt;)?&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;'"&lt;BR /&gt;&lt;BR /&gt;We copied the config from a working V8.1.5 Add-on V5.2.0 system so we can build resiliency using the SQS Queues, but nothing is coming through from the new HF.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 02:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/580534#M102422</guid>
      <dc:creator>Aatom</dc:creator>
      <dc:date>2022-01-11T02:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Addon - SNS Signature</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/580609#M102429</link>
      <description>&lt;P&gt;After reviewing DNS queries, Proxy logs and the VPC Flow logs it turned out that only the SNS service wouldn't use the proxy.&amp;nbsp; I was able to resolve the issue by adding an SNS endpoint to the VPC/Subnet that the Splunk instance is connected to.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 14:21:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/AWS-Addon-SNS-Signature/m-p/580609#M102429</guid>
      <dc:creator>kentsaunders</dc:creator>
      <dc:date>2022-01-11T14:21:46Z</dc:date>
    </item>
  </channel>
</rss>

