I've gotten both the aws add on and the aws app installed. THey're both installed on the heavy forwarded, and both installed on the search head, and the add on is not visible on the search head. I've verified a bunch of data is making it into the index. But the overview panels populate, but not many of the more specific panels. Particularly interested in the security vpc reports, and while I see flow log data in the index, and can run the saved searches which DO generate tables of data, if I view the index they "collect" into, it's empty.
I'm not sure how to track what's going on from this point. I inherited this splunk setup fairly recently.