Splunk Enterprise

CloudTrail Setup

rmadabhushanam
Engager

Hello,

I've been trying to configure Cloud Trail using SplunkforAWS App. Even after completing all steps listed in the USAGE guide, data is not getting populated. Also I do not see any errors anywhere? How should I troubleshoot this? Any guidence for troubleshooting like log file locations or specific configurations would be highly appreciated.

Thanks a lot for your help..

Regards,
Ravi.M

Tags (1)
1 Solution

nkhetia
Path Finder

This has been resolved. what we did is to re-subscribe the SQS queue to SNS topic from SQS screen. Also while configuring CloudTrail inputs :

Select More Settings checkbox.

Set Source type as Manual and specify aws-cloudtrail as Source type.

Under index, select destination index as aws-cloudtrail.

Ravi - Could you accept this and resolve this question ?

thanks
Nilesh

View solution in original post

nkhetia
Path Finder

This has been resolved. what we did is to re-subscribe the SQS queue to SNS topic from SQS screen. Also while configuring CloudTrail inputs :

Select More Settings checkbox.

Set Source type as Manual and specify aws-cloudtrail as Source type.

Under index, select destination index as aws-cloudtrail.

Ravi - Could you accept this and resolve this question ?

thanks
Nilesh

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...