Dashboards & Visualizations

Cloudtrail Data not showing up in SplunkAppforAWS Dashboard

vinodkrishna
New Member

Hi,

Configured SplunkAppForAWS and indexed some data. Data is successfully getting indexed from SQS. But nothing is showing up in SplunkAppForAWS Dashboard. Somebody please help me with this. We use Splunk Version 6.2 with App version 3. Do we need to edit som e configuration file in the Server? Normally where can we find the logs? I couldn't any in /var/log..

Thanks a lot!

Vinod

0 Karma
1 Solution

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

View solution in original post

0 Karma

vinodkrishna
New Member

Thanks a lot for the reply. But how do we manually create a cloudtrail log index.

  1. I consolidated the cloudtrail logs to a file named final.json in the Splunk Server
  2. Created an Index named ( just name) aws-cloudtrail
  3. Under Settings ==> DataInputs==> Selected Files and Directories ==> chose the local final.json file
  4. Selected SourceType and Manual and aws-cloudtrail with Idex Destination Index Field as the newly created one in Step 2.

So Basically I have two types of DataInputs
1. One via Files and Directories
2. Other Via CloudTrail

Both use the newly manually created destination Index created in step 2.

I can see the indexed data in summary , but still not luck through Dashboard.

Thanks!

0 Karma

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...