All Apps and Add-ons

Splunk add on for AWS

henryf
Explorer

Trying to configure Splunk add on for AWS and configure  it, but when creating an input, my AWS account doesn't show it. How can I fix this?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @henryf,

it's very difficoult to help you without viewing your installation!

Anyway, only two stupid questions:

Ciao.

Giuseppe

0 Karma

henryf
Explorer

Hi @gcusello , 

 

Yes I have an active AWS account. The link that you sent me doesn't have specific steps, where exactly do you see that?

 

Thanks,

Henry Foreman

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @henryf ,

in the following pages at the above URL, you find the steps for to configure both AWS instance and Splunk Add-On For AWS.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

in this page https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on is described what you need to do on AWS side to allow Splunk to read data.

r. Ismo

0 Karma

henryf
Explorer

I followed the steps but am still running into an error. I already had an IAM role installed

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have several AWS accounts you must grant access to those alls and/or granting access to your IAM role for doing those queries.

It's really hard try to help you, if only thing what we are knowing is that you have error! We need some logs, error messages etc. 

0 Karma

henryf
Explorer

I only have one account. theres no "error messages", the error is just that its not showing up.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could try to find something from _internal logs. I assume that you are sending those from your HF where your TA-AWS is running. Try something like this and change if/when needed

index=_* OR index=* source=*splunk_ta_aws*

Change also earliest/latest when you are try those logs. 

0 Karma

henryf
Explorer

where exactly do I put that code?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You should write it into Splunk GUI search box.

As there seems to be quite many things which are not so familiar for you, I propose that you will ask help from your local splunk partner or someone who is familiar with AWS, Splunk and Linux.

0 Karma

henryf
Explorer

the log pops up, Now what? Also there's no help number for Splunk and the person I'm talking to said the person that can help me isn't in the office till Monday

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...