Trying to configure Splunk add on for AWS and configure it, but when creating an input, my AWS account doesn't show it. How can I fix this?
Hi @henryf,
it's very difficoult to help you without viewing your installation!
Anyway, only two stupid questions:
Ciao.
Giuseppe
Hi @gcusello ,
Yes I have an active AWS account. The link that you sent me doesn't have specific steps, where exactly do you see that?
Thanks,
Henry Foreman
Hi @henryf ,
in the following pages at the above URL, you find the steps for to configure both AWS instance and Splunk Add-On For AWS.
Ciao.
Giuseppe
Hi
in this page https://docs.splunk.com/Documentation/AddOns/released/AWS/Setuptheadd-on is described what you need to do on AWS side to allow Splunk to read data.
r. Ismo
I followed the steps but am still running into an error. I already had an IAM role installed
If you have several AWS accounts you must grant access to those alls and/or granting access to your IAM role for doing those queries.
It's really hard try to help you, if only thing what we are knowing is that you have error! We need some logs, error messages etc.
I only have one account. theres no "error messages", the error is just that its not showing up.
You could try to find something from _internal logs. I assume that you are sending those from your HF where your TA-AWS is running. Try something like this and change if/when needed
index=_* OR index=* source=*splunk_ta_aws*
Change also earliest/latest when you are try those logs.
where exactly do I put that code?
You should write it into Splunk GUI search box.
As there seems to be quite many things which are not so familiar for you, I propose that you will ask help from your local splunk partner or someone who is familiar with AWS, Splunk and Linux.
the log pops up, Now what? Also there's no help number for Splunk and the person I'm talking to said the person that can help me isn't in the office till Monday.