<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with firehose ingestion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-firehose-ingestion/m-p/469261#M80737</link>
    <description>&lt;P&gt;Hello all...  I am trying to use the Splunk-Trumpet project to a HEC end point with indexer ack, a valid SSL cert and internet facing. I can use curl to POST data to this endpoint with SSL enabled, so this tells me that at the most basic levels my HEC and it's associated infra is setup right. &lt;/P&gt;

&lt;P&gt;Since this sets up an S3 bucket for backup should the firehose fail, i am able to browse that and I see the following message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;Error&amp;gt;
&amp;lt;Code&amp;gt;AccessDenied&amp;lt;/Code&amp;gt;
&amp;lt;Message&amp;gt;Access Denied&amp;lt;/Message&amp;gt;
&amp;lt;RequestId&amp;gt;E1B619A2DC6BDD3F&amp;lt;/RequestId&amp;gt;
&amp;lt;HostId&amp;gt;
pBxYzfWxtG+IfA77uG2ozJ3RNaEf8h4lv83lRDCJ7hmBYU4cPRMSRKk8CxNP761OjONm21jZNLM=
&amp;lt;/HostId&amp;gt;
&amp;lt;/Error&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help is MUCH appreciated, this is a HUGE improvement over the previous ingestion methods. &lt;/P&gt;</description>
    <pubDate>Mon, 23 Dec 2019 18:16:10 GMT</pubDate>
    <dc:creator>brent_weaver</dc:creator>
    <dc:date>2019-12-23T18:16:10Z</dc:date>
    <item>
      <title>Help with firehose ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-firehose-ingestion/m-p/469261#M80737</link>
      <description>&lt;P&gt;Hello all...  I am trying to use the Splunk-Trumpet project to a HEC end point with indexer ack, a valid SSL cert and internet facing. I can use curl to POST data to this endpoint with SSL enabled, so this tells me that at the most basic levels my HEC and it's associated infra is setup right. &lt;/P&gt;

&lt;P&gt;Since this sets up an S3 bucket for backup should the firehose fail, i am able to browse that and I see the following message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;Error&amp;gt;
&amp;lt;Code&amp;gt;AccessDenied&amp;lt;/Code&amp;gt;
&amp;lt;Message&amp;gt;Access Denied&amp;lt;/Message&amp;gt;
&amp;lt;RequestId&amp;gt;E1B619A2DC6BDD3F&amp;lt;/RequestId&amp;gt;
&amp;lt;HostId&amp;gt;
pBxYzfWxtG+IfA77uG2ozJ3RNaEf8h4lv83lRDCJ7hmBYU4cPRMSRKk8CxNP761OjONm21jZNLM=
&amp;lt;/HostId&amp;gt;
&amp;lt;/Error&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help is MUCH appreciated, this is a HUGE improvement over the previous ingestion methods. &lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 18:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-firehose-ingestion/m-p/469261#M80737</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2019-12-23T18:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help with firehose ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-firehose-ingestion/m-p/469262#M80738</link>
      <description>&lt;P&gt;This appears to be some sort of problem with AWS Permission. &lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 00:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-firehose-ingestion/m-p/469262#M80738</guid>
      <dc:creator>badrinath_itrs</dc:creator>
      <dc:date>2019-12-24T00:44:34Z</dc:date>
    </item>
  </channel>
</rss>

