All Apps and Add-ons

Splunk App for AWS 3.0: After manually creating indexes, why are searches against these indexes not returning results?

acclaypool1
Explorer

I am attempting to do a clean install of Splunk 6.2, Splunk Add-on for Amazon Web Services 1.1.0, and Splunk App for AWS 3.0 in order to be able to pull in CloudTrail, Config, and CloudWatch data. In previous version of Splunk App for AWS and Splunk 6.0 setting up the data inputs automatically created indexes named "aws-cloudtrail-index" and "aws-data" (I also created an aws-config-notifications index which appears to be what all the canned panels are configured to search)

It appears that this version does not create these indexes automatically. I have manually created them and changed the index options for my data inputs to use these indexes. Data does appear to be indexed, as events and MBs are increasing. However, any searches against these indexes are returning no results.

I would expect the following search to return all events in the database. It does in my implementation of 6.0 + 2.0, but nothing is returned with the new app.

aws-cloudtrail-index eventName=* | table _time,eventName,userIdentity.userName

Anyone have a working implementation of the new app? Any assistance or guidance would be appreciated.

0 Karma
1 Solution

acclaypool1
Explorer

Of course, after I post the question I see my dumb mistake. Indexes should be "aws-config" and "aws-cloudtrail"

View solution in original post

0 Karma

acclaypool1
Explorer

Of course, after I post the question I see my dumb mistake. Indexes should be "aws-config" and "aws-cloudtrail"

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...