All Apps and Add-ons

Missing Amazon Web Services (AWS) Topology Search, vague documentation

workiswerk
Explorer

AWS 5.1.1 Topology Splunk article (don't have the karma to link).
docs.splunk . com/Documentation/AWS /5 .1.1/User/Topology :

I don't see any such saved search in my Splunk AWS App and have added AWS Config, CloudTrail, and Config Rule inputs. Shouldn't it appear? Or is it a must to include every other input as well? To clarify, I'm not talking about the saved search automatically enabling itself, but rather showing up under Settings > Searches, reports, and alerts at all.

I'm also curious if "aws:config:notification" and "aws:config" types are treated interchangeably or not in the documentation. I have a lot of "aws:config:notification" source types and no pure "aws:config" types. The troubleshooting page for Topology (linked above) mentions that you should search for "sourcetype=aws:config" to ensure data is reaching Splunk; I'm unsure if "aws:config:notification" events are green or red flag for this.

0 Karma

alex_work
New Member

Hi, just curious if you resolved the missing Topology search issue, I'm encountering the same problem. As per documentation I have aws:config data, but i see no saved search  for Config: Topology Data Generator

Cheers

//A

0 Karma

workiswerk
Explorer

Update: aws:config is Config snapshots, which are different from aws:config:notification events.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...