<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS Generic S3 Integration Error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Generic-S3-Integration-Error/m-p/519327#M87824</link>
    <description>&lt;P&gt;Hi, Following is the basic stanza with minimum settings required in &lt;STRONG&gt;inputs.conf&amp;nbsp; &lt;/STRONG&gt;when you use&amp;nbsp;Access Key Id and Secret Access Key.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[aws_s3://test_generic_s3]
aws_account = TestAWSAccount
bucket_name = your-bucket-name
sourcetype = aws:s3:cdr
index = main
host_name = s3.amazonaws.com
polling_interval = 3600&lt;/LI-CODE&gt;&lt;P&gt;File - Splunk_TA_aws/local/passwords.conf should be having your account details stored and encrypted. Same you can find in AWS TA UI section, Configuration -&amp;gt; Accounts. Make sure Account &lt;STRONG&gt;Region Category&lt;/STRONG&gt; is &lt;STRONG&gt;Global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you are using IAM role the stanza is little bit different. What type of Access you have to S3 IAM role/ Access Key id?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 00:54:46 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2020-09-14T00:54:46Z</dc:date>
    <item>
      <title>AWS Generic S3 Integration Error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Generic-S3-Integration-Error/m-p/519121#M87814</link>
      <description>&lt;P&gt;I am attempting to use a Generic S3 Bucket with CDR files with multiple folders inside to visualize the data. I am getting the following error and not sure why the account isn't found. In building the source Splunk autofills the values and I can log into S3 with the account. What logs or remediation should I do?&lt;/P&gt;&lt;P&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\modinputs\generic_s3\aws_s3_data_loader.py", line 86, in index_data&lt;BR /&gt;self._do_index_data()&lt;BR /&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\modinputs\generic_s3\aws_s3_data_loader.py", line 107, in _do_index_data&lt;BR /&gt;self.collect_data()&lt;BR /&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\modinputs\generic_s3\aws_s3_data_loader.py", line 153, in collect_data&lt;BR /&gt;self._discover_keys(index_store)&lt;BR /&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\modinputs\generic_s3\aws_s3_data_loader.py", line 223, in _discover_keys&lt;BR /&gt;credentials = self._generate_credentials()&lt;BR /&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\modinputs\generic_s3\aws_s3_data_loader.py", line 384, in _generate_credentials&lt;BR /&gt;self._config.get(tac.aws_iam_role),&lt;BR /&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\common\aws_credentials.py", line 158, in load&lt;BR /&gt;credentials = self._load(aws_account_name, aws_iam_role_name)&lt;BR /&gt;File "C:\Program Files\Splunk\etc\apps\Splunk_TA_aws\bin\splunk_ta_aws\common\aws_credentials.py", line 169, in _load&lt;BR /&gt;raise AWSAccountError('account not found', aws_account_name)&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;splunk_ta_aws.common.aws_credentials.AWSAccountError: account not found&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 16:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/AWS-Generic-S3-Integration-Error/m-p/519121#M87814</guid>
      <dc:creator>rcrabtree</dc:creator>
      <dc:date>2020-09-11T16:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Generic S3 Integration Error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/AWS-Generic-S3-Integration-Error/m-p/519327#M87824</link>
      <description>&lt;P&gt;Hi, Following is the basic stanza with minimum settings required in &lt;STRONG&gt;inputs.conf&amp;nbsp; &lt;/STRONG&gt;when you use&amp;nbsp;Access Key Id and Secret Access Key.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[aws_s3://test_generic_s3]
aws_account = TestAWSAccount
bucket_name = your-bucket-name
sourcetype = aws:s3:cdr
index = main
host_name = s3.amazonaws.com
polling_interval = 3600&lt;/LI-CODE&gt;&lt;P&gt;File - Splunk_TA_aws/local/passwords.conf should be having your account details stored and encrypted. Same you can find in AWS TA UI section, Configuration -&amp;gt; Accounts. Make sure Account &lt;STRONG&gt;Region Category&lt;/STRONG&gt; is &lt;STRONG&gt;Global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you are using IAM role the stanza is little bit different. What type of Access you have to S3 IAM role/ Access Key id?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 00:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/AWS-Generic-S3-Integration-Error/m-p/519327#M87824</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2020-09-14T00:54:46Z</dc:date>
    </item>
  </channel>
</rss>

