After installing the Splunk Add-on for Amazon Web Services and adding a data input for CloudWatch, why am I getting "Waiting for results..." for searches?

New Member

I have installed the Splunk add-on for AWS (version 1.0.1)

I have successfully setup my account, and have added a data input for CloudWatch, but when I go to search, it just says Waiting for results.. (for Hosts, sources and sourcetypes) which I assume means it is not getting any CloudWatch data.

The input I have created for testing purposes consists of -

AWS Account: {configured AWS account}
AWS Region: ap-southeast-2
Metric namespace: AWS/EC2
Metricnames: ["CPUUTilization"]
Dimension names: {"InstanceID" : "i-c******"}
Metric statistics being requested: ["Average","Sum","Maximum","Minimum"]
Metric granularity: 60 (detailed monitoring is enabled)
Minimum polling interval: 60

There does not seem to be any errors in the aws_cloudwatch log, just lots of:

2015-02-06 11:04:01,298 INFO pid=3448 tid=MainThread | query work queued = 0, deferred = 0 , scan_time = 0.000s

The IAM user that Splunk is using has full access to CloudWatch.

I can't seem to find any troubleshooting information or people experiencing the same issue, so any help would be much appreciated.

We intend to use Splunk in an enterprise environment but this is a blocker.

Thanks in advance!

Splunk Version ............................................6.2.0
Splunk Build ............................................237341

Splunk Employee
Splunk Employee

Hi, I hadn't seen this before, sorry.

  1. It's a supported add-on, so opening a ticket is the best move if you don't hear back on a post.
  2. With 1.1.0 we added a debug logging mode.
  3. That log entry says it's not getting any messages from the queue. Besides the usual permissions questions, an interesting potential cause of that is multiple consumers of the queue.
