Last week, I started a Splunk Cloud 14-day Trial to do a POC for ingesting AWS Cloudwatch Logs to Splunk Cloud using IAM Roles.
AWS had documents on this topic, however, their approach is to create an IAM User and Splunk Add-on for AWS. I don't want to create IAM User since that will lead to secret access key management and rotation.
So my approach is to use IAM Role. I found some documents on using IAM Role, and it require to set up certain things. The set up is provided as guideline in the "Data Manager" app.
However, I can't seem to find the app. The only data related app I see is Data Management, which has the options to create Connections. Basically, I am looking for this app: Onboard AWS in Data Manager | Splunk Cloud Platform (last updated 2025-06-30T14:00:18.163Z)
I saw another document stated that since Splunk Cloud 10.4, the app is renamed to Data Inputs. But I could not search for app with such name either.
If there is option to use IAM Roles with Splunk Add-on for AWS, I would also appreciate if someone can guide me to use it
Hi @Na_Kang_Lim
Data Manager is not available on Splunk Cloud Platform trial instances. For a trial environment, use the Splunk Add-on for Amazon Web Services app instead as @gcusello mentions
To set this up:
I believe trial stacks are a single SH so an nslookup/ping should resolve the external IP for you.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.
How can I use IAM Roles and set up Trust Policy if I use that app?