All Apps and Add-ons

Splunk Add-on for AWS error: Not data collection tasks for aws_description is discovered. Doing nothing and quitting the

georgec24
Observer

Hello, I have an Enterprise instance in an EC2 instance (all in one box, free trial) and trying to get CloudTrail logs to it using the "Splunk Add-on for AWS" (S3 Bucket > Event Notification > SNS > SQS > EC2 Instance with IAM Role ). In the logs from _internal I see that the files are picked up from S3 ( message="Wrote data to STDOUT success.", message="Sent data for indexing.",  message="Delete SQS message" etc. ) but then I get only these messages:  message="No data input has been configuredexiting..." and  message="Not data collection tasks for aws_description is discovered. Doing nothing and quitting the TA.". The CloudTrail logs do not show up in main indexer or anywhere else so everything is lost somewhere after this <<message="Sent data for indexing.">>

Again, everything is in one box in EC2 (Splunk Enterprise free trial). If anyone has a solution to this, it would be greatly appreciated, thanks!

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...