Splunk Search

AWS Config data in Splunk

amitshrigoel
Explorer

I am trying to query AWS config data in Splunk to identify the names of all S3 buckets in AWS. Is there a way to write a SPL that will list out the S3 bucket names from t

0 Karma

ezamit
Explorer

I have attached the raw data to the post. I am trying the following query to identify the ResourceTypes and the count but it is not giving me any results :

index=app_shared source=aws.config | stats count by resourceType | table resourceType

I think we can also narrow down to only -  "detail-type": "Config Configuration Item Change"

0 Karma

PaulPanther
Motivator

Please provide sample data to help you with the search query

0 Karma

ezamit
Explorer

I have attached the raw data to the post. I am trying the following query to identify the ResourceTypes and the count but it is not giving me any results :

index=app_shared source=aws.config | stats count by resourceType | table resourceType

I think we can also narrow down to only -  "detail-type": "Config Configuration Item Change"

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...