All Apps and Add-ons

Splunk App and Add-on for AWS: Why are we unable to get data from a specific sub sourcetype inside AWS description?


We are not getting data from the specific sub source type inside AWS description -- ELB , all other sources such as EBS is working fine. We configured it in Splunk App for AWS thru metadata. Any Advice.
We are seeing this error in Splunk with this search : index=_internal ERROR sourcetype="aws:description:log"

12:09:50.518 PM 
2016-12-21 17:09:50,518 ERROR pid=5326 tid=Thread-9 | Failed to collect description data for elastic_load_balancers, error=Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/description_mod/", line 66, in index_data
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/description_mod/", line 86, in _do_index_data
    results = self._api(task)
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/description_mod/", line 59, in load_balancers
    instances = elb_conn.describe_instance_health(
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/boto/ec2/elb/", line 554, in describe_instance_health
    [('member', InstanceState)])
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/boto/", line 1186, in get_list
    raise self.ResponseError(response.status, response.reason, body)
BotoServerError: BotoServerError: 400 Bad Request
ErrorResponse xmlns="">
    Message>Rate exceeded</Message>
0 Karma

Splunk Employee
Splunk Employee

Which Addon version are you using? The Throttling issue has been fixed in the latest version.

0 Karma



So we contacted splunk support for this, their respond:
In order to rectify this, you will need to contact Amazon and discuss increasing your API call limit with them.
AWS respond:
The API limit is measured per account (all IAM users and Services) and cannot be changed. This is to protect all customers and maintain a stable environment which is fair to all customers

See the dilemma here , you are saying : The Throttling issue has been fixed in the latest version ??

0 Karma


Our current Add -on version is 4.1.1 and Splunk app aws is 4.2.1 .

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...