Hello, has anyone figured out this issue? I face something similar. I have an Enterprise instance in an EC2 instance (all in one box, free trial) and trying to get CloudTrail logs to it using the "Splunk Add-on for AWS" (S3 Bucket > Event Notification > SNS > SQS > EC2 Instance with IAM Role ). In the logs from _internal I see that the files are picked up from S3 ( message= " Wrote data to STDOUT success . ", message= " Sent data for indexing . ", message= " Delete SQS message " etc. ) but then I get only these messages: message= " No data input has been configured , exiting... " and message= " Not data collection tasks for aws_description is discovered. Doing nothing and quitting the TA. ". The CloudTrail logs do not show up in main indexer or anywhere else so everything is lost somewhere after this << message= " Sent data for indexing . ">> Again, everything is in one box in EC2 (Splunk Enterprise free trial). If anyone has a solution to this, it would be greatly appreciated, thanks!
... View more