Dashboards & Visualizations

Cloudtrail Data not showing up in SplunkAppforAWS Dashboard

vinodkrishna
New Member

Hi,

Configured SplunkAppForAWS and indexed some data. Data is successfully getting indexed from SQS. But nothing is showing up in SplunkAppForAWS Dashboard. Somebody please help me with this. We use Splunk Version 6.2 with App version 3. Do we need to edit som e configuration file in the Server? Normally where can we find the logs? I couldn't any in /var/log..

Thanks a lot!

Vinod

0 Karma
1 Solution

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

View solution in original post

0 Karma

vinodkrishna
New Member

Thanks a lot for the reply. But how do we manually create a cloudtrail log index.

  1. I consolidated the cloudtrail logs to a file named final.json in the Splunk Server
  2. Created an Index named ( just name) aws-cloudtrail
  3. Under Settings ==> DataInputs==> Selected Files and Directories ==> chose the local final.json file
  4. Selected SourceType and Manual and aws-cloudtrail with Idex Destination Index Field as the newly created one in Step 2.

So Basically I have two types of DataInputs
1. One via Files and Directories
2. Other Via CloudTrail

Both use the newly manually created destination Index created in step 2.

I can see the indexed data in summary , but still not luck through Dashboard.

Thanks!

0 Karma

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...