All Apps and Add-ons

Splunk Addon For AWS SNS Topic Code fails for external AWS Accounts

splunkme3
Engager

Has anyone had an issue with posting to an external AWS account's SNS topic? External being an account different from where your Splunk instance's IAM role lives. I have noticed that the SNS Topic alert action is limited to only SNS Topics where the IAM lives. I have submitted the following idea to Splunk. 

Splunk Addon For AWS Code Modification avoid listTopics in SNS | Ideas

If anyone has been able to get the alert action to post to an external account using their IAM role, please share your solution here. If not, an up vote on the idea would be much appreciated. I see it as a simple fix for the app to make it more flexible. 

Also submitted a case with Splunk detailing the issue: Case: 3812674 | Splunk

Labels (3)
Tags (3)
0 Karma

ghantk
New Member

I had the similar use-case, we have used SNS(from local)->SNS(different account). https://docs.aws.amazon.com/sns/latest/dg/sns-create-subscribe-endpoint-to-topic.html 

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...