Hi,
Configured SplunkAppForAWS and indexed some data. Data is successfully getting indexed from SQS. But nothing is showing up in SplunkAppForAWS Dashboard. Somebody please help me with this. We use Splunk Version 6.2 with App version 3. Do we need to edit som e configuration file in the Server? Normally where can we find the logs? I couldn't any in /var/log..
Thanks a lot!
Vinod
The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.
Thanks a lot for the reply. But how do we manually create a cloudtrail log index.
So Basically I have two types of DataInputs
1. One via Files and Directories
2. Other Via CloudTrail
Both use the newly manually created destination Index created in step 2.
I can see the indexed data in summary , but still not luck through Dashboard.
Thanks!
The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.