All Apps and Add-ons

IT Essentials App

drggfish
Engager

Hello - I just moved my Splunk deployment to AWS and installed a couple of apps - (1) Splunk App for AWS and (2) IT Essentials.

In several of the IT Essentials built in queries it is referencing:

sourcetype="aws:description"

Where is this sourcetype coming from?

Thanks,

Greg

Labels (2)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @drggfish 

The aws:description sourcetype comes from the Splunk Add-on for Amazon Web Services (AWS)

However, Splunk Add-on for AWS has deprecated the usage of the aws:description source type and currently supports the use of the aws:metadata source type to get data in for versions 6.0.0 or later. For more information, see the documentation about the different source types that Splunk Add-on for AWS supports in Source types for the Splunk Add-on for AWS.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

drggfish
Engager

Thanks!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @drggfish 

The aws:description sourcetype comes from the Splunk Add-on for Amazon Web Services (AWS)

However, Splunk Add-on for AWS has deprecated the usage of the aws:description source type and currently supports the use of the aws:metadata source type to get data in for versions 6.0.0 or later. For more information, see the documentation about the different source types that Splunk Add-on for AWS supports in Source types for the Splunk Add-on for AWS.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...