Splunk Enterprise

Splunk App for AWS - no accounts in configure tab

justingschumach
New Member

This is a fresh install of Splunk Lite, and the AWS App for Splunk (latest of both as of today).
It is running on an EC2 ubuntu instance with an EC2 role that (for the purposes of testing) has Administrator level access.
I have added .aws/config credentials and environment variables for access and secret keys. I can use aws cli without issue to access all the AWS services.

After installing the AWS App for Splunk, I did not get any data at all in any of the dashboards. Looking at the documentation, it suggested I go to the Configure tab to modify users. I do not see any user related information there, only Billing.

I'm fairly new to Splunk, and apologize if this is a simple question. I didn't see anything posted that answered the question as yet.

Thank you kindly for your help.

Labels (3)
Tags (1)
0 Karma

justingschumach
New Member

I would appreciate any help with this. I would like to use Splunk, but can't until I can resolve this.

I have also tried the same steps as above on a Debian linux EC2 instance with Enterprise and could not get any data with the AWS App for Splunk plugin there either.

I don't see anything that helped me in the logs in $Splunkhome/var/log/splunk/*

Many thanks.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...