<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CloudTrail data not showing in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162542#M98054</link>
    <description>&lt;P&gt;Yes, it's resolved now. I was also able to figure out a more limiting ACL for the access keys rather than the Power User policy. You can limit access to just the queue created in SQS as follows:&lt;/P&gt;

&lt;P&gt;{&lt;BR /&gt;
  "Version": "2012-10-17",&lt;BR /&gt;
  "Statement":[{&lt;BR /&gt;
      "Effect":"Allow",&lt;BR /&gt;
      "Action":"sqs:*",&lt;BR /&gt;
      "Resource":"arn:aws:sqs:us-east-1:&lt;ACCOUNTNUMBER&gt;:&lt;QUEUENAME&gt;"&lt;BR /&gt;
      }&lt;BR /&gt;
  ]&lt;/QUEUENAME&gt;&lt;/ACCOUNTNUMBER&gt;&lt;/P&gt;

&lt;P&gt;}&lt;/P&gt;</description>
    <pubDate>Tue, 03 Dec 2013 01:36:16 GMT</pubDate>
    <dc:creator>alanwill</dc:creator>
    <dc:date>2013-12-03T01:36:16Z</dc:date>
    <item>
      <title>CloudTrail data not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162540#M98052</link>
      <description>&lt;P&gt;I'm using Splunk 6 with the Splunk for AWS app and trying to configure it to show CloudTrail data. I've created the SNS topic and SQS queue and can see messages in the queue but nothing is coming over to the Splunk index. The CloudTrail Log input is created, the keys are for an IAM user that has full describe access on the entire account, and I've tried entering the queue name both as the canonical name and the full arn. &lt;/P&gt;

&lt;P&gt;Any idea what I'm missing or why this still isn't working?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
&lt;EM&gt;alan&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:55:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162540#M98052</guid>
      <dc:creator>alanwill</dc:creator>
      <dc:date>2013-12-02T17:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: CloudTrail data not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162541#M98053</link>
      <description>&lt;P&gt;This issue has been resolved.  IAM user didn't have enough permission to fetch data.  &lt;/P&gt;

&lt;P&gt;Allan,   Could you resolve this question ?&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
Nilesh&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 01:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162541#M98053</guid>
      <dc:creator>nkhetia</dc:creator>
      <dc:date>2013-12-03T01:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: CloudTrail data not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162542#M98054</link>
      <description>&lt;P&gt;Yes, it's resolved now. I was also able to figure out a more limiting ACL for the access keys rather than the Power User policy. You can limit access to just the queue created in SQS as follows:&lt;/P&gt;

&lt;P&gt;{&lt;BR /&gt;
  "Version": "2012-10-17",&lt;BR /&gt;
  "Statement":[{&lt;BR /&gt;
      "Effect":"Allow",&lt;BR /&gt;
      "Action":"sqs:*",&lt;BR /&gt;
      "Resource":"arn:aws:sqs:us-east-1:&lt;ACCOUNTNUMBER&gt;:&lt;QUEUENAME&gt;"&lt;BR /&gt;
      }&lt;BR /&gt;
  ]&lt;/QUEUENAME&gt;&lt;/ACCOUNTNUMBER&gt;&lt;/P&gt;

&lt;P&gt;}&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 01:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CloudTrail-data-not-showing-in-Splunk/m-p/162542#M98054</guid>
      <dc:creator>alanwill</dc:creator>
      <dc:date>2013-12-03T01:36:16Z</dc:date>
    </item>
  </channel>
</rss>

