Getting Data In

Splunk Add-on for AWS ARN Format Mismatch

tkw03
Communicator

Hello

In setting up the add on for AWS(4.6.1) in the IAM role setup it expects a role ARNin the format of :

arn:aws-us-gov:iam::12345566789:role/XXX_GuardDuty_S3_XXX

 But the ARN I got from AWS is formatted like this:
arn:aws-us-gov.iam:12345566789:role/XXX_GuardDuty_S3_XXX

Notice the difference between "gov.iam" to "gov:iam" and "iam:123" to "iam::123"

 

I had to change the ARN to be able to get the selection added into the app BUT I assume it wont work since the ARN isnt correct since the format isnt right.

Any ideas on how to work around it?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...