Hi All,
i am a bit puzzeled. I know that connecting to a foreign AWS account via user credentials is in itself a bit of an open issue (security wise), but it should work. And it does work for the Instance "Splunk Obeservability", however it does not for self hosted instance of Splunk Enterprise.
So both instances use the same user and therefore same policies.
I saw a post from way back that you should eliminate all namespaces not needed anyhow. So I did and am left with two namespaces/dimensions i know should fetch information => AWS/EC2, AWS/EBS.
I also have a local AMI Role for my local AWS account which works just fine, even with dimensions not used in AWS.
There is however one abnormality in the logs:
Input via Splunk_AWS_Role works great, but input with Cross_Splunk_Connection delivers no data, but also does not log any errors.
Any help is very much appreciated.
Kind regards,
Mike