I've been trying to get the Splunk App for AWS working by following the Splunk docs but I cannot get any of the Cloudwatch data to be ingested. I'm receiving aws:cloudtrail, aws:description, aws:billing and aws:config just fine so I must be doing something right?
This help page - http://docs.splunk.com/Documentation/AWS/5.0.2/Installation/ConfigureyourAWSservices - says that there is no further configuration for the cloudwatch data to be ingested by Splunk, so I am clearly missing something. Any advice would be greatly appreciated.
Thanks in advance
Have you looked in your internal logs for any messages from the app while it is doing the cloudwatch pull? They are quite informative.