All Apps and Add-ons

Any recommendations on how to proceed with the installation of AWS Add On in Splunk?

SplunkDash
Motivator

Hello,

Do you have any recommendations on how to proceed with the installation of AWS Add On in SPLUNK. Does REST API call from AWS Add on needs to have any Authentication Token?

Thank you so much for your support in advance.

 

Labels (1)
Tags (1)
0 Karma
1 Solution

caiosalonso
Path Finder

Since you already have the Key ID, Secret Key and an IAM role, I guess you can use then to configure the AWS Add-on on your Heavy Forwarder, no problem. I would recommend creating a separate user and role just for security reasons, but if this is not an issue in your environment there is no problem in usnig the existing ones.

You just need to make sure the IAM role will have the necessary permissions for each kind of input you plan to add.

I recommend you to follow the steps on the following docs:

Add an AWS account: https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on#Add_and_manage_AWS_accounts 

Add an IAM role: https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on#Add_and_manage_IAM_roles

View solution in original post

caiosalonso
Path Finder

Hi,

If you are installing the Splunk Add-on for AWS, you will need to configure an IAM role and create a user with an access key (the add-on needs the Key ID and Secret Key). The following link describes what you need in order to configure an AWS account in the add-on: https://docs.splunk.com/Documentation/AddOns/latest/AWS/Setuptheadd-on

SplunkDash
Motivator

Hello,

Thank you so much for your quick response and the important resources you provided, truly appreciate it.

I have one group of people they have IAM role configured and created a user with an access key and already Installed AWS-Add-On on their Cloud Server/host. Is it possible for me to use the same credentials like Key ID and Secret Key to Install AWS-Add-On  on my On-Prem HF? Thank you again!

Tags (1)
0 Karma

caiosalonso
Path Finder

Since you already have the Key ID, Secret Key and an IAM role, I guess you can use then to configure the AWS Add-on on your Heavy Forwarder, no problem. I would recommend creating a separate user and role just for security reasons, but if this is not an issue in your environment there is no problem in usnig the existing ones.

You just need to make sure the IAM role will have the necessary permissions for each kind of input you plan to add.

I recommend you to follow the steps on the following docs:

Add an AWS account: https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on#Add_and_manage_AWS_accounts 

Add an IAM role: https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on#Add_and_manage_IAM_roles

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...