Building for the Splunk Platform

Cloudtrail Log Input doesn't exist

cchsiang2002
Explorer

Hello,

I have installed the Splunk App for AWS. Billing and instance data are successfully being generated. I am looking to pull data from Cloudtrail next. After installation, the data input for AWS Cloudtrail Log does not appear. Splunk version is 6.0.2. Is there a config I am missing?

Thanks in advance.

Tags (1)
0 Karma
1 Solution

atanasoffa
Explorer

Solved - the issue is that the Splunk DBConnect app interferes with the modular input for Cloudtrail - so the input is hidden at https://[server_name]/en-US/manager/search/data/inputs/aws-cloudtrail. The fix is to update the DBConnect app if it exists and the Cloudtrail input will appear when navigating to Data Inputs.

View solution in original post

0 Karma

atanasoffa
Explorer

Solved - the issue is that the Splunk DBConnect app interferes with the modular input for Cloudtrail - so the input is hidden at https://[server_name]/en-US/manager/search/data/inputs/aws-cloudtrail. The fix is to update the DBConnect app if it exists and the Cloudtrail input will appear when navigating to Data Inputs.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...