@tsmit, thanks for the quick reply. From the Inputs tab, I am able to see the more informative UI that you included in your screenshot. I'm not sure what you mean by "the same one you setup your Account with in the Splunk Add-On." We have a couple of AWS accounts that are currently being used by AWS SQS-Based S3 Inputs. They were setup from the Configuration -> Account page, and appear in the 'AWS Account' drop down. Presumably, I could setup another account with the appropriate permissions to assume a role, and then specify that account and the role for 'AWS Account' and 'Assume Role', respectively. However, if an IAM user is required to assume a role, then it probably makes sense to just attach the policy directly to the user since we lose the advantages of using an IAM role.
... View more