All Apps and Add-ons

IT Essentials App

drggfish
Engager

Hello - I just moved my Splunk deployment to AWS and installed a couple of apps - (1) Splunk App for AWS and (2) IT Essentials.

In several of the IT Essentials built in queries it is referencing:

sourcetype="aws:description"

Where is this sourcetype coming from?

Thanks,

Greg

Labels (2)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @drggfish 

The aws:description sourcetype comes from the Splunk Add-on for Amazon Web Services (AWS)

However, Splunk Add-on for AWS has deprecated the usage of the aws:description source type and currently supports the use of the aws:metadata source type to get data in for versions 6.0.0 or later. For more information, see the documentation about the different source types that Splunk Add-on for AWS supports in Source types for the Splunk Add-on for AWS.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

drggfish
Engager

Thanks!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @drggfish 

The aws:description sourcetype comes from the Splunk Add-on for Amazon Web Services (AWS)

However, Splunk Add-on for AWS has deprecated the usage of the aws:description source type and currently supports the use of the aws:metadata source type to get data in for versions 6.0.0 or later. For more information, see the documentation about the different source types that Splunk Add-on for AWS supports in Source types for the Splunk Add-on for AWS.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...