Hello,
I'm evaluating Splunk Light for some light-weight log parsing. One of the needs I have is the ability to monitor resources in AWS.
To that end, I installed the Splunk App for AWS and the Splunk Add-On for Amazon Web Services.
When trying to follow the instructions for configuring accounts, after clicking "Configure", I am presented with a screen that has a single button for "Billing" (Select billing tag) on it and a row of check-boxes for "Warning Message Settings". There is no option to set up an account or any other configurable option.
Looking in the Splunk errors, I see that AdminManageExternal is not supported by Splunk Light.
I'm not sure if the two are related or not., but I cannot figure out how to set up an Splunk Light to use an AWS account so I can starting inputting data from AWS.
Any help would be greatly appreciated.
In Splunk Light 7.0, here are the steps for using the Splunk App for AWS and Splunk Add-on for AWS, and adding AWS accounts and configuring inputs:
Thank you very much. You have been huge help! I'm not able to award points for some reason but you should get them!!!!
Is this fixed for Splunk Cloud also?
You're welcome.
I just tested Splunk Cloud (not Splunk Light cloud service) and it seems to work fine. The steps are similar as what I posted for Splunk Light. Confirm you have both the Splunk App for AWS and the Splunk Add-on for AWS installed/enabled.
Steps:
1. Install/Add the "Splunk Add-on for AWS" and the "Splunk App for AWS". (These are available from the Apps gear icon on the main page. Search for AWS and find the app and add-on. Install both, restart, and open the Splunk Add-on for AWS to configure) .
Go to the Splunk Add-on for AWS (from the top drop down menu), and click Configuration in top menu bar.
Click Add in the right of the screen to add your AWS accounts.
Click "Inputs" in the top menu bar.
In the Create New Input dropdown menu on the right of the screen, select the data type you want to create and follow the instructions to configure the input. .
To see your dashboards, select the Splunk App for AWS in the top dropdown menu.
Hope this helps!
@networkthinking -- re your comment "not able to award points" -- are you able to "Accept" the answer? If not we can file a bug report. Let me know!
We are investigating the UI issues with the App/Addon in Splunk light.
All inputs are now configured using the addon and not the app.
You can access the specific pages using:
You can access those at:
https://cloudinstance.cloud.splunk.com/en-US/app/Splunk_TA_aws/inputs
For account configuration...
https://cloudinstance.cloud.splunk.com/en-US/app/Splunk_TA_aws/configuration
Ok If you are using Splunk Add-on for AWS v4.4.0 and v5.1.0 version of the app - the configuration has to be done in the add-on and No longer allowed in the Splunk App in AWS. What you have described as behavior for the configuration tab is expected and it looks like you are doing the configuration in app.
Can you please confirm if you are having issues doing the configuration on the add-on instead?
We have been using the Splunk App for AWS and clicking the Config button. The Config button does not seem to work anymore in Cloud or Light since 5.1
Do you have document on how to add data to Splunk using AWS? I looked around in the Splunk Add-on and could not find a space to add our accounts
Please advise or share document on how this has changed so we can get our data into Splunk Light or Cloud.
I checked this document and still shows to use the Configure button
http://docs.splunk.com/Documentation/SplunkLight/6.6.3/Installation/GettingstartedSplunkAppforAWS#
Is there a new doc we should be using?
Step 4: In Splunk Light, add your AWS account and configure data sources
In your Splunk Light instance, add at least one AWS account to use for data collection, and configure your data sources (inputs) to get your AWS data into Splunk Light. You will need your AWS Account Access Key ID and AWS Secret Access Key. Splunk suggests you configure all the data sources listed to populate all dashboards. Each data source has instructions in the user dialog about how to add and configure the input.
The configuration for adding AWS accounts is now through the Add-on for AWS, from the Data>Data Input page in Splunk Light. I'm working on a doc update and it should be available in the next day or so after information is confirmed.
Gayle - I found the screen you are referencing but not sure which option to choose to add the AWS account. Can you add that here so we can move forward? We have been stuck since Friday on this and our ticket is not being touched in the support system.
What about in Splunk Cloud. It is also different since the Config button no longer works.
I just sent you an email.
For Splunk Light 7.0, these work-around steps should guide you in adding an AWS account and configuring services.
See the Learn more link within the dialog, or Inputs overview for the Splunk App for AWS for information about specific data sources.
To resolve this issue, it's best to log a Support ticket at this time. Go to www.splunk.com and click Support > Support Portal in upper right. Thanks.
Thanks. We opened case 548415 this weekend and waiting for update from Splunk.
I heard back from Support but appears that person is not familiar with the Splunk App for AWS. We will wait to see if we can get any resolution to this. I am starting to get the feeling this is not something considered Production or used very widely. Not sure how there can only be two of us reporting this .
I am having same issue. We had three accounts and was going to add more this morning when I was prompted to install updates for Splunk AWS. After I installed it I had same error as you.
I also decided to try Splunk Cloud to see if I had same issue. Immediate after installing the AWS apps I was unable to add accounts. I have a feeling new version of AWS app is breaking cloud and light versions.
Hello,
Anyone come up with an answer on this?
Looking into this issue, and will post findings after a bit more research.
Hi Mike, Can you email me a screenshot of the issue you are having. Also, I have some other resources for you that might be helpful.
Thanks,
gneumann@splunk.com
Where did you get your version of Splunk Light? Is it a trial version from Splunk.com, or did you install the Splunk Light AMI version from the AWS Marketplace for Splunk products?
The reason I ask is if you get your Splunk Light AMI version, now "Splunk Insights for AWS Cloud Monitoring AMI", the AWS app and add-on are pre-installed. See https://aws.amazon.com/marketplace/pp/B015ZG2196?qid=1506376905168&sr=0-2&ref_=srh_res_product_title. You might not have the issues you are currently having. It seems something might be wrong with the configuration of the AWS app and add-on in your current instance?