Getting Data In

Can not find Data Manager App

Na_Kang_Lim
Path Finder

Last week, I started a Splunk Cloud 14-day Trial to do a POC for ingesting AWS Cloudwatch Logs to Splunk Cloud using IAM Roles.

AWS had documents on this topic, however, their approach is to create an IAM User and Splunk Add-on for AWS. I don't want to create IAM User since that will lead to secret access key management and rotation.

So my approach is to use IAM Role. I found some documents on using IAM Role, and it require to set up certain things. The set up is provided as guideline in the "Data Manager" app.

However, I can't seem to find the app. The only data related app I see is Data Management, which has the options to create Connections. Basically, I am looking for this app: Onboard AWS in Data Manager | Splunk Cloud Platform (last updated 2025-06-30T14:00:18.163Z)

I saw another document stated that since Splunk Cloud 10.4, the app is renamed to Data Inputs. But I could not search for app with such name either.

If there is option to use IAM Roles with Splunk Add-on for AWS, I would also appreciate if someone can guide me to use it

Labels (4)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Na_Kang_Lim 

Data Manager is not available on Splunk Cloud Platform trial instances. For a trial environment, use the Splunk Add-on for Amazon Web Services app instead as @gcusello mentions  

To set this up:

  • Create an IAM User with programmatic access keys, and configure the user in the add-on under Configuration > Account.
  • Set up an IAM Role containing the required CloudWatch read permissions, configured with a trust policy that allows the IAM User to assume it.
  • If security is a concern regarding IAM users/keys, add an IP restriction condition (aws:SourceIp) to the IAM policy to restrict calls strictly to your Splunk Cloud outbound public IP addresses. This mitigates key exposure risks while still enabling the add-on to pull data.

I believe trial stacks are a single SH so an nslookup/ping should resolve the external IP for you. 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Na_Kang_Lim ,

Use the "Splunk Add-on for AWS".

Ciao.

Giuseppe

0 Karma

Na_Kang_Lim
Path Finder

How can I use IAM Roles and set up Trust Policy if I use that app?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...