I have the Splunk add-on for Amazon Web Services v 8.0.0 installed on a Heavy Forwarder and we have several inputs working okay currently.
We were using aws-description input in add-on version 5, and now want to ingest these events again.
After configuring the input in version 8.0.0 we are seeing the - "Conf file(s) passwords.conf changed, exiting"
The passwords.conf file is being constantly updated when we have the input enabled.
The add-on is configured to use the IAM role to collect from logs the AWS account.
P.S. When we change the apps logging to DEBUG or ERROR, we either get the same level of logging or less (less when we change to ERROR) 😕
Also should have mentioned that we have set up a 'metadata' input for the first time as 'description' has been depreciated in this new add-on version.