Splunk Enterprise

Unable to parse message

taka
Explorer

I used Splunk Add on for AWS to send log files stored in S3 to SQS using S3 event notifications, and configured Splunk to read the log files from SQS.

127f8442-ec25-4753-a79b-1f3d2ae825ea.png

 

However, I got an error saying that the S3 test message that is always sent first by S3 event notifications could not be parsed.

スクリーンショット 2024-04-12 9.58.09.png

 

Splunk on EC2 is given KMS decryption privileges as shown below.

 

            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": [
				"sqs:*",
                "s3:*",
                "kms:Decrypt"
            ],
            "Resource": [
				"arn:aws:sqs:ap-northeast-1:*************:poc-splunk-vpcflowlog*",
                "arn:aws:s3:::poc-splunk-vpcflowlog",
                "arn:aws:s3:::poc-splunk-vpcflowlog/*"

 

 

What could be the cause?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...