All Apps and Add-ons

How do you get aws:cloudwatch working in the Splunk AWS App?

jamin358
Explorer

I've been trying to get the Splunk App for AWS working by following the Splunk docs but I cannot get any of the Cloudwatch data to be ingested. I'm receiving aws:cloudtrail, aws:description, aws:billing and aws:config just fine so I must be doing something right?

  • I've checked my permissions so that in my aws policy, I have permissions for everything that the aws app needs - following http://docs.splunk.com/Documentation/AWS/5.0.2/Installation/ConfigureyourAWSpermissions.
  • In my AWS add-on, I have in my inputs a cloudwatch input type with the correct account and role with the above permissions.
  • In AWS, I have also ticked the "Receive Billing Alerts" button in the Billing Management Preferences Page.

This help page - http://docs.splunk.com/Documentation/AWS/5.0.2/Installation/ConfigureyourAWSservices - says that there is no further configuration for the cloudwatch data to be ingested by Splunk, so I am clearly missing something. Any advice would be greatly appreciated.

Thanks in advance

0 Karma

stefanhutchison
Explorer

Have you looked in your internal logs for any messages from the app while it is doing the cloudwatch pull? They are quite informative.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...