All Apps and Add-ons

splunk addon for aws does not list s3 buckets

charry
Engager

I have configured my aws logging account with splunk. The logging account has a centralized s3 bucket for cloudtrail logs collection from all aws accounts in the organization. while i'm able to create a 'description' input and it shows the s3 buckets in the account, splunk does not detect any s3 buckets in the account when i try to configure a new input for either cloudtrail or custom-data with Generic S3 or Incremental S3. i've verified that my IAM user/role and bucket policies are correct by using the same user/role on aws cli to list buckets/objects etc. any suggestions please?

Tags (1)

jordanking1992
Path Finder

I am facing the same issue. Any solution?

0 Karma

jawaharas
Motivator

This should be due to Account permission issue in AWS. Regarding AWS account, are you Key ID/ Secret Key or Role-based access?

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...