All Apps and Add-ons

Splunk Add-on for Amazon Web Services: Why can't I get the metrics for every period that I defined for Amazon Cloudwatch?

jmallorquin
Builder

Hello,

I am using the Splunk Add-on for Amazon Web Services and it is already configured, but I can't get the metrics for every period that I defined.
I have used several define inputs about changing the dimensions but same result. Any body knows how to configure the dimensions to get the statistic of one metric, and also if is needed to create one input per balancername per metric per statistic or is possible to query all of them together.

The stanza that I use is:

[aws_cloudwatch://axxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx]
aws_account = aws-es00
aws_region = eu-west-1
host = axxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
index = customer_index
metric_dimensions = [{"axxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"}]
metric_names = ["Latency"]
metric_namespace = AWS/ELB
period = 300
polling_interval = 600
sourcetype = aws:cloudwatch
statistics = ["Average"]

can anybody help me?

Also i have used the cli of amazon and i cant get all statistics of selected metric of with this command
aws cloudwatch get-metric-statistics --metric-name Latency --namespace AWS/ELB --start-time 2015-01-22T00:00:00 --end-time 2015-01-23T00:00:00 --period 600 --statistics Average --dimensions Name=LoadBalancerName,Value=xxxxxxxxxxxxx

ppablo
Retired

Hi @jmallorquin

I saw that you closed this post because an answer was found and accepted, but didn't see an answer below. Did you find a solution elsewhere and if yes, could you please add that answer and accept it to resolve the post?

0 Karma

jmallorquin
Builder

Hi Ppablo_splunk

Yes finally i conact with Amazon support, the reason why splunk has gaps of infomation, is becouse in my environment there wasn't data.

Splunk contact to Amazon by cloudwath and if in cloudwath dont have information about it... they dont send anything.

0 Karma

lding_splunk
Splunk Employee
Splunk Employee

would you mind to paste the debug log of the add-on for cloudwatch using below SPL, to see any kind errors?

  index=_internal source=*aws_cloudwatch.log
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...