Hello!
I'm using the full-feature AWS Organization. It allows to create an aggregator that contains Config data from all accounts and regions in the organization.
Is it possible to get this data into Splunk using Splunk Ann-on for AWS? I can't find a good option for it.
Of course, I can create a bucket with all the config data from all accounts, but it requires a lot of effort and seems unreasonable.
Maybe it is possible to create an input which utilize
get-aggregate-resource-config
method? It looks much easier to query a single API endpoint than set up data collection from different sources to one place. BTW, it can be a good substitution to Describe with Assume Role inputs.