Hello, we use the AWS AddOn for Splunk for all of our AWS Inputs.
For a few months, after many years of this showing correctly, we no longer see data under this search:
sourcetype=aws:config:notification configurationItem.resourceType = AWS::S3::Bucket
The thing is, nothing changed other than updates to the AWS AddOn. AND we still get data under here for every resourceType that I can think of EXCEPT S3, so the AWS side configuration and the inputs I have to assume are set fine.
sourcetype=aws:config:notification
I have looked over this in every facet I can think possible and have had a support case open for a while now. Any thoughts or similar cases? Thanks!