Splunk Search

AWS Config data in Splunk

amitshrigoel
Explorer

I am trying to query AWS config data in Splunk to identify the names of all S3 buckets in AWS. Is there a way to write a SPL that will list out the S3 bucket names from t

0 Karma

ezamit
Explorer

I have attached the raw data to the post. I am trying the following query to identify the ResourceTypes and the count but it is not giving me any results :

index=app_shared source=aws.config | stats count by resourceType | table resourceType

I think we can also narrow down to only -  "detail-type": "Config Configuration Item Change"

0 Karma

PaulPanther
Motivator

Please provide sample data to help you with the search query

0 Karma

ezamit
Explorer

I have attached the raw data to the post. I am trying the following query to identify the ResourceTypes and the count but it is not giving me any results :

index=app_shared source=aws.config | stats count by resourceType | table resourceType

I think we can also narrow down to only -  "detail-type": "Config Configuration Item Change"

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...