Splunk Search

awsAddOn sourcetype=aws:config:notification configurationItem.resourceType = AWS::S3::Bucket no Longer Showing

mcweens
Engager

Hello, we use the AWS AddOn for Splunk for all of our AWS Inputs.

For a few months, after many years of this showing correctly, we no longer see data under this search:

sourcetype=aws:config:notification configurationItem.resourceType = AWS::S3::Bucket

The thing is, nothing changed other than updates to the AWS AddOn.  AND we still get data under here for every resourceType that I can think of EXCEPT S3, so the AWS side configuration and the inputs I have to assume are set fine.

sourcetype=aws:config:notification

 

I have looked over this in every facet I can think possible and have had a support case open for a while now.  Any thoughts or similar cases?  Thanks!

0 Karma
Get Updates on the Splunk Community!

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...