Splunk Enterprise

Apache access logs stored on a s3 bucket access

Said75015
Explorer

Hi

I have configured Splunk AWS plugin to get files stored in a s3 bucket. These files come from a Apache server and have Apache access log format. 

I use an s3 generic input and it seems to be connected (I tried with only one file) but when I check for searching events I don't see anything ? Internal Splunk logs indicate the s3 bucket is well reached and the file inside well processed without error.

Do you have a idea  from which this issue can be due ?

Thanks

Saïd

Labels (1)
0 Karma
1 Solution

Said75015
Explorer

Hi @venkatasri 

I have found the issue, it was just due to the fact that I used a too recent time interval (my records concerned an older time) so there was nothing displayed.

Thanks

View solution in original post

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

Can you share how your inputs have been configured? You can anonymize the bucket name.

 

Said75015
Explorer

Hi @venkatasri 

I have found the issue, it was just due to the fact that I used a too recent time interval (my records concerned an older time) so there was nothing displayed.

Thanks

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...