All Apps and Add-ons

Is there a way to bypass the auto listing of S3 buckets?

CaptivaBlueTeg
New Member

For the Splunk Add-on for AWS when adding a new input using the Generic S3, as soon as the AWS account is entered it goes into loading for the S3 bucket as it tries to list all. The issue is, the vendor has blocked listing all buckets for security reasons. Key and special key are given to access the assigned bucket to this account.

What are the options to get around this in the Splunk App since Field S3 Bucket is required and unable to manually enter the bucket name given? This is Splunk Cloud also, so the ability to manually add an input.conf is not an option.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...