All Apps and Add-ons

Splunk Add-on for AWS error: Not data collection tasks for aws_description is discovered. Doing nothing and quitting the

georgec24
Observer

Hello, I have an Enterprise instance in an EC2 instance (all in one box, free trial) and trying to get CloudTrail logs to it using the "Splunk Add-on for AWS" (S3 Bucket > Event Notification > SNS > SQS > EC2 Instance with IAM Role ). In the logs from _internal I see that the files are picked up from S3 ( message="Wrote data to STDOUT success.", message="Sent data for indexing.",  message="Delete SQS message" etc. ) but then I get only these messages:  message="No data input has been configuredexiting..." and  message="Not data collection tasks for aws_description is discovered. Doing nothing and quitting the TA.". The CloudTrail logs do not show up in main indexer or anywhere else so everything is lost somewhere after this <<message="Sent data for indexing.">>

Again, everything is in one box in EC2 (Splunk Enterprise free trial). If anyone has a solution to this, it would be greatly appreciated, thanks!

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...