All Apps and Add-ons

Resource Activity Dashboard is not working in Splunk AWS App

Ajinkya1992
Path Finder

Hi Team,
We could see Configuration changes Trellis populating data on Overview dashboards in Splunk App for Aws. But once we tried drilling it down to Resource Activity monitor, then there is no single panel which is populating data for the same.
We tried investigating search query for changes over time
aws-config-notification( (aws_account_id="*") , (region="*") ) configurationItem.resourceType=TERM(*) configurationItemDiff.changeType=DELETE | timechart count by configurationItemDiff.changeType

In this query all macros are working but query is failing at configurationItem.resourceType=TERM(*) configurationItemDiff.changeType=DELETE | timechart count by configurationItemDiff.changeType

Could you please help me to understand what actions do i need to take?
Also we did some trial and error basis troubleshooting like working with Field Aliases but it fails.
So we tried creating fields aliases for testing purpose which works with Search app but it is not working for aws app (we have rectified permission issue but dont think anything is wrong with it)

0 Karma

lznger88_2
Path Finder

Hi,

Did you end up resolving this issue? I also have the same problem.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...