Getting Data In

S3 App is not able to fetch logs

darshan_singh01
Path Finder

Hi ,

While integrating Splunk (via S3 app) with AWS S3 ,we are finding the below error .

A connection attempt failed because connected party did not properly respond after a period of time or connected host has failed to respond”.

We are not able to add the bucket info from Splunk Web and from config file .The environment we have is a cluster environment on Splunk 5.0.5 .Is it possible to have an issue related to Port blocking etc ?? Our environment is in AWS VPC .
Early response would be really appreciable ...

0 Karma

darshan_singh01
Path Finder

thanks ...

Could you confirm on which port S3 bucket will be connected ?

0 Karma

darshan_singh01
Path Finder

thanks ...

Could you confirm on which port S3 bucket will be connected ?

0 Karma

bsheppard_splun
Splunk Employee
Splunk Employee

I asked a colleague for suggestions. What the error indicates is that whatever reason, the Splunk add-on can't make a call to the S3 bucket. It could be a firewall or VPC configuration, or other AWS permissions. Most often, an error like that is usually is caused by something like a firewall.

One other idea. Look in the splunkd.log ($SPLUNK_HOME/var/log/splunk/splunkd.log) and see if the input had posted any additional information there. The S3 input is actually pretty simple, so there's usually not much that can go wrong other than connectivity (or a typo).

Hope these help at least narrow down your trouble shooting.

Happy Splunking,

Brett

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...