Splunk Enterprise

Search for data in an aws s3 bucket doesn't show any data

Said75015
Explorer

Hi,

I have configured an input through aws splunk plugin to get data from a s3 bucket but when I search for it it don't show me anything.

I use the test license (I'm trying a POC with the solution)

Connection configuration is ok since I can list files in the bucket from splunk interface.

Thanks for your help

Saïd

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

I guess you must have used AWS Add-on from splunkbase to configure the s3 inputs. You can find the issues underlying with this query accordingly you can troubleshoot.

index=_internal sourcetype=aws:s3:log ERROR

---

An upvote would be appreciated and Accept solution if this reply helps!

View solution in original post

Tags (1)

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

I guess you must have used AWS Add-on from splunkbase to configure the s3 inputs. You can find the issues underlying with this query accordingly you can troubleshoot.

index=_internal sourcetype=aws:s3:log ERROR

---

An upvote would be appreciated and Accept solution if this reply helps!

Tags (1)
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...