All Apps and Add-ons

Unable to use Splunk local endpoint as cloudwatch destination

karthi25
Path Finder

I am working with streaming cloudwatch logs to splunk. Splunk is my local instance with SSL enabled. I am trying to make my splunk local endpoint as destination to firehose delivery stream as follows:

alt text

and in the command line am creating cloudwatch destination

aws logs put-destination --destination-name "awslogs-destination-splunk" --target-arn "arn:aws:firehose:us-east-1:arnno:deliverystream/firehose-splunk-delivery-stream" --role-arn "arn:aws:iam::arnno:role/cw-to-kinesis-role"

but it showing me the error as follows:

An error occurred (InvalidParameterException) when calling the PutDestination op
eration: Could not deliver test message to specified destination. Check if the d
estination is valid.

What am doing wrong here.Can anyone please suggest me the solution for it.

0 Karma

toddwpiper
Engager

Hi, did you ever figure this one out? I have the same issue.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...