Dashboards & Visualizations

Cloudtrail Data not showing up in SplunkAppforAWS Dashboard

vinodkrishna
New Member

Hi,

Configured SplunkAppForAWS and indexed some data. Data is successfully getting indexed from SQS. But nothing is showing up in SplunkAppForAWS Dashboard. Somebody please help me with this. We use Splunk Version 6.2 with App version 3. Do we need to edit som e configuration file in the Server? Normally where can we find the logs? I couldn't any in /var/log..

Thanks a lot!

Vinod

0 Karma
1 Solution

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

View solution in original post

0 Karma

vinodkrishna
New Member

Thanks a lot for the reply. But how do we manually create a cloudtrail log index.

  1. I consolidated the cloudtrail logs to a file named final.json in the Splunk Server
  2. Created an Index named ( just name) aws-cloudtrail
  3. Under Settings ==> DataInputs==> Selected Files and Directories ==> chose the local final.json file
  4. Selected SourceType and Manual and aws-cloudtrail with Idex Destination Index Field as the newly created one in Step 2.

So Basically I have two types of DataInputs
1. One via Files and Directories
2. Other Via CloudTrail

Both use the newly manually created destination Index created in step 2.

I can see the indexed data in summary , but still not luck through Dashboard.

Thanks!

0 Karma

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...