Dashboards & Visualizations

Cloudtrail Data not showing up in SplunkAppforAWS Dashboard

vinodkrishna
New Member

Hi,

Configured SplunkAppForAWS and indexed some data. Data is successfully getting indexed from SQS. But nothing is showing up in SplunkAppForAWS Dashboard. Somebody please help me with this. We use Splunk Version 6.2 with App version 3. Do we need to edit som e configuration file in the Server? Normally where can we find the logs? I couldn't any in /var/log..

Thanks a lot!

Vinod

0 Karma
1 Solution

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

View solution in original post

0 Karma

vinodkrishna
New Member

Thanks a lot for the reply. But how do we manually create a cloudtrail log index.

  1. I consolidated the cloudtrail logs to a file named final.json in the Splunk Server
  2. Created an Index named ( just name) aws-cloudtrail
  3. Under Settings ==> DataInputs==> Selected Files and Directories ==> chose the local final.json file
  4. Selected SourceType and Manual and aws-cloudtrail with Idex Destination Index Field as the newly created one in Step 2.

So Basically I have two types of DataInputs
1. One via Files and Directories
2. Other Via CloudTrail

Both use the newly manually created destination Index created in step 2.

I can see the indexed data in summary , but still not luck through Dashboard.

Thanks!

0 Karma

acclaypool1
Explorer

The new app indexes to "default" index upon installation now (rather than automatically creating a aws-cloudtrail index). I manually created the index (deleted the old index from app 2.0). Then change the manual settings on the input to index to the correct place and all was set.

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...