All Apps and Add-ons

After installing the Splunk Add-on for Amazon Web Services and adding a data input for CloudWatch, why am I getting "Waiting for results..." for searches?

77gm77
New Member

I have installed the Splunk add-on for AWS (version 1.0.1)

I have successfully setup my account, and have added a data input for CloudWatch, but when I go to search, it just says Waiting for results.. (for Hosts, sources and sourcetypes) which I assume means it is not getting any CloudWatch data.

The input I have created for testing purposes consists of -

AWS Account: {configured AWS account}
AWS Region: ap-southeast-2
Metric namespace: AWS/EC2
Metricnames: ["CPUUTilization"]
Dimension names: {"InstanceID" : "i-c******"}
Metric statistics being requested: ["Average","Sum","Maximum","Minimum"]
Metric granularity: 60 (detailed monitoring is enabled)
Minimum polling interval: 60

There does not seem to be any errors in the aws_cloudwatch log, just lots of:

2015-02-06 11:04:01,298 INFO pid=3448 tid=MainThread file=aws_cloudwatch.py:stream_events:952 | query work queued = 0, deferred = 0 , scan_time = 0.000s

The IAM user that Splunk is using has full access to CloudWatch.

I can't seem to find any troubleshooting information or people experiencing the same issue, so any help would be much appreciated.

We intend to use Splunk in an enterprise environment but this is a blocker.

Thanks in advance!

Splunk Version ............................................6.2.0
Splunk Build ............................................237341

0 Karma

miteshvohra
Contributor

Here is the list of links for easy access:

Hope this helps.

Mitesh.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, I hadn't seen this before, sorry.

  1. It's a supported add-on, so opening a ticket is the best move if you don't hear back on a post.
  2. With 1.1.0 we added a debug logging mode.
  3. That log entry says it's not getting any messages from the queue. Besides the usual permissions questions, an interesting potential cause of that is multiple consumers of the queue.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...