Alerting

AWS Add-on for Splunk: Configure Regions in the inputs.conf file

nathanr123
New Member

Hello,

I'm trying to configure the CloudTrail and CloudWatch data inputs to collect AWS logs for Splunk. When I select a region that I think is correct, there is no log data coming into Splunk.

When I go into the inputs.conf file manually and input the region that was assigned to my programs account, still, no log data. 

I even went in configured an index for the AWS add-on, went into the meta-data and changed the saved searches/macros to point to the new index I created, etc. 

Has anyone experienced this issue before?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...