All Apps and Add-ons

Configure AWS Guardduty Logs

wvalente
Explorer

Guys,

I'm trying to set up Guardduty log collection, but so far I'm not successful.

I have a heavy forwarder that forwards logs to the indexer and the search head queries the data in the indexer.

I configured the add-ons on the necessary platforms (heavy forwarder and search head), I configured the accounts needed to forward the logs.

The logs are being sent via the SQS queue. The logs arrive at the indexer, but I can't get the dashboard populated (Splunk App for AWS and aws_guardduty).

On the dashboards, in the 'AccountID' menu, a message appears
"Search produced no results."

I also tried to configure via HEC, but there is an error message that it cannot connect to the platform.

Can someone help me?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...