I've deployed an architecture with a centralized s3 bucket that forwards AWS logs to an SQS queue. In Splunk side, I have an enterprise edition, already installed the Splunk Add-ons for AWS, set the input as Custom>SQS and Configurations as follows:
- account number, access keys
- IAM role with assume role permissions.
I stil can't get logs in Splunk, any guidance for trouble-shooting? Also, is it possible to share a reference example of SQS access policies?
Thanks