- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Setting up secure access between Enterprise Splunk to external 3rd party AWS S3
ran
Observer
11-16-2023
01:16 AM
Hi all,
I am new to SPLUNK and would appreciate some community wisdom. We are trying to get data from an external AWS s3 bucket (hosted and managed by 3rd party supplier) onto our internal enterprise SPLUNK instance. We do not have any AWS accounts.
We have considered whitelisting but it is not secure enough.
The supplier does not use AWS firehose
Any ideas?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
11-16-2023
04:39 AM
Is this what you're looking for?
https://docs.splunk.com/Documentation/AddOns/released/AWS/S3
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ran
Observer
11-16-2023
05:00 AM
Not sure if this will work because the Add-On requires us to to have AWS account.
We don't have or manage any AWS accounts.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
11-16-2023
05:02 AM
I don't think you can access a bucket without having any accounts (and subsequently being given access to that bucket). But I might be wrong, I'm not an AWS expert.
