Splunk Enterprise

smartstore indexes.conf

sky12345sky1
Explorer

I am testing the SmartStore setup on S3 with Splunk Enterprise running on an EC2 instance.

I am attempting this with an IAM role that has full S3 access.

When I included the access keys in indexes.conf and started the instance, SmartStore successfully started.

However, when I assigned the IAM role permissions to the EC2 instance and removed the key information from indexes.conf, Splunk froze at the loading screen with indexes.conf....

Running AWS commands shows that various files from S3 are listed.

Below is the indexes.conf. During the loading process, Splunk freezes and does not start. The splunkd.log shows a shutdown message at the end. If I re-enter the key information in indexes.conf, it works again. I want to operate this using the IAM role.

 

[default]
remotePath = volume:rstore/$_index_name
[volume:rstore]
storageType = remote
path = s3://S3バケット名
remote.s3.endpoint = https://s3.ap-northeast-1.amazonaws.com

q1.png

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This site implies the remote.s3.endpoint setting is not needed.  https://blog.arcusdata.io/how-to-set-up-splunk-smart-store-in-aws

See https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/SmartStoresecuritystrategies#Authenticate... for AWS permissions that must be granted to the role.

---
If this reply helps you, Karma would be appreciated.

PaulPanther
Motivator

Could you please check your splunkd.log for any error events and share them?

0 Karma

sky12345sky1
Explorer

Thank you

below is splunkd.log 

 

09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_HttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down name="HttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_DmcProxyHttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_Duo2FAHttpClient"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_S3ConnectionPoolManager"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down name="S3ConnectionPoolManager"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down level="ShutdownLevel_AwsSdk"
09-20-2024 06:36:54.626 +0000 INFO Shutdown [2498 Shutdown] - shutting down name="loader"
09-20-2024 06:36:54.628 +0000 INFO Shutdown [2498 Shutdown] - Shutdown complete in 5.124 seconds
09-20-2024 06:36:54.629 +0000 INFO loader [2296 MainThread] - All pipelines finished.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...