All Apps and Add-ons

Splunk App for AWS 3.0: After manually creating indexes, why are searches against these indexes not returning results?

acclaypool1
Explorer

I am attempting to do a clean install of Splunk 6.2, Splunk Add-on for Amazon Web Services 1.1.0, and Splunk App for AWS 3.0 in order to be able to pull in CloudTrail, Config, and CloudWatch data. In previous version of Splunk App for AWS and Splunk 6.0 setting up the data inputs automatically created indexes named "aws-cloudtrail-index" and "aws-data" (I also created an aws-config-notifications index which appears to be what all the canned panels are configured to search)

It appears that this version does not create these indexes automatically. I have manually created them and changed the index options for my data inputs to use these indexes. Data does appear to be indexed, as events and MBs are increasing. However, any searches against these indexes are returning no results.

I would expect the following search to return all events in the database. It does in my implementation of 6.0 + 2.0, but nothing is returned with the new app.

aws-cloudtrail-index eventName=* | table _time,eventName,userIdentity.userName

Anyone have a working implementation of the new app? Any assistance or guidance would be appreciated.

0 Karma
1 Solution

acclaypool1
Explorer

Of course, after I post the question I see my dumb mistake. Indexes should be "aws-config" and "aws-cloudtrail"

View solution in original post

0 Karma

acclaypool1
Explorer

Of course, after I post the question I see my dumb mistake. Indexes should be "aws-config" and "aws-cloudtrail"

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...