All Apps and Add-ons

Splunk add on for AWS

henryf
Explorer

Trying to configure Splunk add on for AWS and configure  it, but when creating an input, my AWS account doesn't show it. How can I fix this?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @henryf,

it's very difficoult to help you without viewing your installation!

Anyway, only two stupid questions:

Ciao.

Giuseppe

0 Karma

henryf
Explorer

Hi @gcusello , 

 

Yes I have an active AWS account. The link that you sent me doesn't have specific steps, where exactly do you see that?

 

Thanks,

Henry Foreman

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @henryf ,

in the following pages at the above URL, you find the steps for to configure both AWS instance and Splunk Add-On For AWS.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

in this page https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on is described what you need to do on AWS side to allow Splunk to read data.

r. Ismo

0 Karma

henryf
Explorer

I followed the steps but am still running into an error. I already had an IAM role installed

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have several AWS accounts you must grant access to those alls and/or granting access to your IAM role for doing those queries.

It's really hard try to help you, if only thing what we are knowing is that you have error! We need some logs, error messages etc. 

0 Karma

henryf
Explorer

I only have one account. theres no "error messages", the error is just that its not showing up.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could try to find something from _internal logs. I assume that you are sending those from your HF where your TA-AWS is running. Try something like this and change if/when needed

index=_* OR index=* source=*splunk_ta_aws*

Change also earliest/latest when you are try those logs. 

0 Karma

henryf
Explorer

where exactly do I put that code?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You should write it into Splunk GUI search box.

As there seems to be quite many things which are not so familiar for you, I propose that you will ask help from your local splunk partner or someone who is familiar with AWS, Splunk and Linux.

0 Karma

henryf
Explorer

the log pops up, Now what? Also there's no help number for Splunk and the person I'm talking to said the person that can help me isn't in the office till Monday. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...