Hi All,
I have installed the Splunk Add-on for AWS and I am able to ingest S3 logs into Splunk, but the dashboards are not working. When I look at the fields, I can see a lot of them are appearing with a pre-fix of Records{}.
E.g., Records{}.requestID, Records{}.eventType etc...
I believe this is affecting the search. I don't see any errors in the log
Has anyone experienced this? I am hoping someone can point me to the right direction to fix it.
Cheers,
Michael.
Hi, IIRC that's the format that you get from CloudTrail when there are multiple accounts writing into one bucket (http://docs.splunk.com/Documentation/AddOns/latest/AWS/ConfigureInputs#CloudTrail_inputs) -- newer versions of the Add-on should parse those records, but an older version would leave the records wrapper on.