Splunk Search

Current Month Estimated Billing not displaying Account ID in drop-down

nehaprasad14
New Member

Unable to get billing details in Splunk App for AWS. I have configured the billing input in Splunk Add-on apps.

Tags (1)
0 Karma

adonio
Ultra Champion

do you have billing data?
https://docs.splunk.com/Documentation/AddOns/released/AWS/ConfigureAWS#Configure_billing
try and search index = * sourcetype = aws:billing OR sourcetype = aws:billing:cur

0 Karma

nehaprasad14
New Member

Yes, I already did this step. I am getting the search results in Splunk Add-on App. But its not displaying in the same data in my Splunk App for AWS.

0 Karma

adonio
Ultra Champion

did you verify the search returned results?
what index does the data sits in?
does your user role searches that index by default?

0 Karma

nehaprasad14
New Member

Yes, this is my search criteria : index = "main" sourcetype = "aws:billing" OR sourcetype = "aws:billing:cur"
and this is the results:
4,417 events (7/1/18 12:00:00.000 AM to 7/19/18 6:21:58.000 PM)

0 Karma

nehaprasad14
New Member

But when I go to Splunk App for AWS -> Billing. It does not produces any search results nor does it populate my Account Id

0 Karma

nehaprasad14
New Member

Thanks for your help.. I figured the issue.. My AWS reports configuration was not proper.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...