File /opt/splunk/etc/apps/s3/README/inputs.conf.spec:
[s3://umi-mf-cdnlogs]
key_id = AKIA
secret_key = EOW5NUqjoJ
~
~
does that bucket have a contain called tiles-cdn?
I've got an input for cloudfront:
[s3://freesoft001]
key_id = AKIA
# This is Amazon key ID.
secret_key = riuvl
# This is the secret key.
sourcetype=freesoft_cloudfront
which captures my S3 logs no problem. freesoft001 has a container called cloud-front, and Splunk successfully traverses down into it, but it doesn't show up on my inputs screen.