Getting Data In

Data onboarding issue - Splunk_TA_aws

smakwana
Explorer

Hi,

I am trying to onboard aws access logs from a S3 bucket using the Splunk Add-on for AWS installed in a Heavy Forwarder. There are logs in the location. I am giving a start time stamp as one of the logs. There are more logs in that location, but logs are not getting onboarded into Splunk. I don't see any error logs in _internal logs. 

Labels (1)
0 Karma
1 Solution

thahir
Contributor

@smakwana go to this path $SPLUNK_HOME/var/log/splunk/splunk_ta_aws_s3.log and check if there is any error related to the add on. 

Make sure you gave the correct permission in the AWS end and assigned the List bucket and Get object policy for the S3 bucket.

 

 

View solution in original post

0 Karma

thahir
Contributor

@smakwana go to this path $SPLUNK_HOME/var/log/splunk/splunk_ta_aws_s3.log and check if there is any error related to the add on. 

Make sure you gave the correct permission in the AWS end and assigned the List bucket and Get object policy for the S3 bucket.

 

 

0 Karma

smakwana
Explorer

Thank you, Thahir

Updated permissions to the role accessing the S3 bucket and that fixed the issue.

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@smakwana - I don't think the given information is enough to understand the issue, given the complexity and variety in AWS inputs. Please provide more details.

* Are you using SQS-based S3 input?

* What are your input settings?

* Is your SQS configured correctly?

* etc

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...