Hi, I'm trying to configure "custom Data Type" > SQS input in Splunkadd-onforAWS app to onboard data from an AWS account. is it possible to create the SQS input using IAM role instead of a...
I am trying to set up SplunkAdd-onforAWS to pull my logs from my AWS account into splunk. I have a Splunk Enterprise setup on prem in an AWS EC2 server. I used theSplunk Enterprise AMI. I have a...
...hen I go into theinputs.conf file manually and inputthe region that was assigned to my programs account, still, no log data. I even went in configured an index fortheAWSadd-on, went into the...
...ppname/Inputs despite this is not defined anywhere in my default.xml that I created on SHD. I dig a little bit and found that /Inputs are defined in SplunkforAWSAddon's default.xml that is a...
...ay to configuretheadd-on to pull the logs from this s3 bucket... there are so many input options but we tried S3 Inputs/Access Logs/Generic S3 with the account and role...
Hello I am collecting data via AWSaddon and what I have found is that my timestamp recognition isn't working properly. I have a single AWSinput using the [aws:s3:csv] sourcetype. this the...
I'm trying to configure a cloudwatch logs input but I continue to receive invalid key errors when restarting Splunkonthe HF. I've gone by the doc as well as opened a support case but haven't had s...
Hi - I am trying to get theSplunk App forAWS Security Dashboards working. Apparently the default index the app is using is "main". I need to change this. I know I could c...
...instance. There is an awsSplunkadd-in splunkbase , are we able to use this add-on to pull data from a third-party aws account , if so how is it authenticated against third-party account? P...