All Apps and Add-ons

Cloudtrail aws-cloudtrail.py error

atanasoffa
Explorer

Hello:

I am trying to ingest Cloudtrail data into Splunk App for AWS. When i look at the internal logs for this script, I get the following errors regarding the run() method in the script:

ERROR ExecProcessor - message from "python /apps/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py" KeyError: 'Message'
ERROR ExecProcessor - message from "python /apps/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py" message = json.loads(envelope["Message"])
ERROR ExecProcessor - message from "python /apps/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py" File "/apps/splunk/etc/apps/SplunkAppforAWS/bin/aws-cloudtrail.py", line 205, in run

Has anyone remediated this already?

Thanks in advance.

0 Karma
1 Solution

grinabms
Explorer

BTW, I checked my old splunkd.log files, and that's exactly the error message I was getting. The fix in the other thread solved my problem.

-Pete

View solution in original post

0 Karma

grinabms
Explorer

BTW, I checked my old splunkd.log files, and that's exactly the error message I was getting. The fix in the other thread solved my problem.

-Pete

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...