Splunk Enterprise

smartstore indexes.conf

sky12345sky1
Explorer

I am testing the SmartStore setup on S3 with Splunk Enterprise running on an EC2 instance.

I am attempting this with an IAM role that has full S3 access.

When I included the access keys in indexes.conf and started the instance, SmartStore successfully started.

However, when I assigned the IAM role permissions to the EC2 instance and removed the key information from indexes.conf, Splunk froze at the loading screen with indexes.conf....

Running AWS commands shows that various files from S3 are listed.

Below is the indexes.conf. During the loading process, Splunk freezes and does not start. The splunkd.log shows a shutdown message at the end. If I re-enter the key information in indexes.conf, it works again. I want to operate this using the IAM role.

 

[default]
remotePath = volume:rstore/$_index_name
[volume:rstore]
storageType = remote
path = s3://S3バケット名
remote.s3.endpoint = https://s3.ap-northeast-1.amazonaws.com

q1.png

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This site implies the remote.s3.endpoint setting is not needed.  https://blog.arcusdata.io/how-to-set-up-splunk-smart-store-in-aws

See https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/SmartStoresecuritystrategies#Authenticate... for AWS permissions that must be granted to the role.

---
If this reply helps you, Karma would be appreciated.

PaulPanther
Motivator

Could you please check your splunkd.log for any error events and share them?

0 Karma

sky12345sky1
Explorer

Thank you

below is splunkd.log 

 

09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_HttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down name="HttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_DmcProxyHttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_Duo2FAHttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_S3ConnectionPoolManager"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down name="S3ConnectionPoolManager"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_AwsSdk"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down name="loader"
09-20-2024 06:36:54.628 +0000 INFO Shutdown [2498 Shutdown] - Shutdown complete in 5.124 seconds
09-20-2024 06:36:54.629 +0000 INFO loader [2296 MainThread] - All pipelines finished.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...