All Apps and Add-ons

Cant add CloudTrail(SQS based S3) to AWS addons for AWS.

Sorok71
Engager

We are using Splunk CLoud and need to integrate it with our AWS accounts. The whole scheme of integrations looks like
https://cloudcraft.co/view/e3810740-7b15-4d3c-9484-fb7cc9e8bb23?key=Bf6ssGDBu5IRZ__eBW9d3g

I've created Policy "Configure one policy containing permissions for all inputs" https://docs.splunk.com/Documentation/AddOns/released/AWS/ConfigureAWSpermissions

also granted the user to delegate permissions for this role to IAM users.

Add admin account in AWS addons for AWS > Configuration > Account
I set the admin account just for testing for making sure that User has all privileges that can we need.

But when I am trying to add new Input CloudTrail(SQS based S3) I got an error:

Unexpected error "" from python handler: "HTTP 404 Not Found -- {"messages":[{"type":"ERROR","text":"Could not find object id=assume_role"}]}". See splunkd.log for more details.
https://www.screencast.com/t/JRXWXXGuUX

I've also trying to set the Role here. The same result. Also, as I understand Role is using for checking other linked AWS accounts to the current one.

logs queue has available messages

I will appreciate any help

Tags (4)

mlogendra_splun
Splunk Employee
Splunk Employee

Please try changing the app permissions to Global. It fixed the problem in my case

vinkumar_splunk
Splunk Employee
Splunk Employee

This has worked for me, thank you!

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...