All Apps and Add-ons

Splunk App for AWS: topology tsidx does not get created

cmeo
Contributor

More of a comment for the developers since I've solved it.

The saved search Config: Topology Data Generator does not seem to get run at any point unless you do it manually, and until you do the Topology view doesn't populate. Does this step perhaps need to be included in the setup documentation, or is it supposed to run automatically somehow? There's no schedule for it so I don't see how, and tt isn't called by the dashboard as far as I can tell.

0 Karma

fshao_splunk
Splunk Employee
Splunk Employee

Hi,

Thank you for your comment !

The savedsearch in AWS App is non-scheduled at first place (which is a practice we need to follow). And you can enable it by any modifications of "AWS Config" on configuration page, then, the topology data will be generated by schedule automatically. It will run every 20 minutes.

For more information about it, please refer to http://docs.splunk.com/Documentation/AWS/4.0.0/Installation/Config

Thanks!

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...