- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk add on for AWS
Trying to configure Splunk add on for AWS and configure it, but when creating an input, my AWS account doesn't show it. How can I fix this?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @henryf,
it's very difficoult to help you without viewing your installation!
Anyway, only two stupid questions:
- did you configured an account before creating an input?
- did you followed all the steps of the procedure at https://docs.splunk.com/Documentation/AddOns/released/AWS/Description ?
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @gcusello ,
Yes I have an active AWS account. The link that you sent me doesn't have specific steps, where exactly do you see that?
Thanks,
Henry Foreman
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @henryf ,
in the following pages at the above URL, you find the steps for to configure both AWS instance and Splunk Add-On For AWS.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi
in this page https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on is described what you need to do on AWS side to allow Splunk to read data.
r. Ismo
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I followed the steps but am still running into an error. I already had an IAM role installed
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

If you have several AWS accounts you must grant access to those alls and/or granting access to your IAM role for doing those queries.
It's really hard try to help you, if only thing what we are knowing is that you have error! We need some logs, error messages etc.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I only have one account. theres no "error messages", the error is just that its not showing up.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

You could try to find something from _internal logs. I assume that you are sending those from your HF where your TA-AWS is running. Try something like this and change if/when needed
index=_* OR index=* source=*splunk_ta_aws*
Change also earliest/latest when you are try those logs.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
where exactly do I put that code?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

You should write it into Splunk GUI search box.
As there seems to be quite many things which are not so familiar for you, I propose that you will ask help from your local splunk partner or someone who is familiar with AWS, Splunk and Linux.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the log pops up, Now what? Also there's no help number for Splunk and the person I'm talking to said the person that can help me isn't in the office till Monday.
