Splunk Search

AWS Config data in Splunk

amitshrigoel
Explorer

I am trying to query AWS config data in Splunk to identify the names of all S3 buckets in AWS. Is there a way to write a SPL that will list out the S3 bucket names from t

0 Karma

ezamit
Explorer

I have attached the raw data to the post. I am trying the following query to identify the ResourceTypes and the count but it is not giving me any results :

index=app_shared source=aws.config | stats count by resourceType | table resourceType

I think we can also narrow down to only -  "detail-type": "Config Configuration Item Change"

0 Karma

PaulPanther
Motivator

Please provide sample data to help you with the search query

0 Karma

ezamit
Explorer

I have attached the raw data to the post. I am trying the following query to identify the ResourceTypes and the count but it is not giving me any results :

index=app_shared source=aws.config | stats count by resourceType | table resourceType

I think we can also narrow down to only -  "detail-type": "Config Configuration Item Change"

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...