Splunk Enterprise

Search for data in an aws s3 bucket doesn't show any data

Said75015
Explorer

Hi,

I have configured an input through aws splunk plugin to get data from a s3 bucket but when I search for it it don't show me anything.

I use the test license (I'm trying a POC with the solution)

Connection configuration is ok since I can list files in the bucket from splunk interface.

Thanks for your help

Saïd

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

I guess you must have used AWS Add-on from splunkbase to configure the s3 inputs. You can find the issues underlying with this query accordingly you can troubleshoot.

index=_internal sourcetype=aws:s3:log ERROR

---

An upvote would be appreciated and Accept solution if this reply helps!

View solution in original post

Tags (1)

venkatasri
SplunkTrust
SplunkTrust

Hi @Said75015 

I guess you must have used AWS Add-on from splunkbase to configure the s3 inputs. You can find the issues underlying with this query accordingly you can troubleshoot.

index=_internal sourcetype=aws:s3:log ERROR

---

An upvote would be appreciated and Accept solution if this reply helps!

Tags (1)
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...