Splunk Enterprise

Search for data in an aws s3 bucket doesn't show any data

Said75015
Explorer

Hi,

I have configured an input through aws splunk plugin to get data from a s3 bucket but when I search for it it don't show me anything.

I use the test license (I'm trying a POC with the solution)

Connection configuration is ok since I can list files in the bucket from splunk interface.

Thanks for your help

Saïd

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

I guess you must have used AWS Add-on from splunkbase to configure the s3 inputs. You can find the issues underlying with this query accordingly you can troubleshoot.

index=_internal sourcetype=aws:s3:log ERROR

---

An upvote would be appreciated and Accept solution if this reply helps!

View solution in original post

Tags (1)

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

I guess you must have used AWS Add-on from splunkbase to configure the s3 inputs. You can find the issues underlying with this query accordingly you can troubleshoot.

index=_internal sourcetype=aws:s3:log ERROR

---

An upvote would be appreciated and Accept solution if this reply helps!

Tags (1)
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...