All Apps and Add-ons

Splunk App for AWS: Why does creating a S3 input with nested folder structure not return any results?

ytenenbaum_splu
Splunk Employee
Splunk Employee

A Splunk customer using Splunk App for AWS and they have a problem with the S3 input. They did a few tests to check that the S3 Input is ingesting data and it was able to collect files from a single bucket (.txt files) without any issues. However, when they create an S3 Input and target it to a bucket that contains nested folder structure they're not getting any results, the logs in the buckets do not have any extension as such. They have tried this with ELB Access logs and Cloudtrail logs.

0 Karma
1 Solution

ytenenbaum_splu
Splunk Employee
Splunk Employee

They've solved it by adding a Bucket policy that allows the role to do an S3:GetObject on the Bucket. They overlooked this originally and this is what caused the issue. It appears to be working fine now and they're getting logs coming in nicely.

View solution in original post

ytenenbaum_splu
Splunk Employee
Splunk Employee

They've solved it by adding a Bucket policy that allows the role to do an S3:GetObject on the Bucket. They overlooked this originally and this is what caused the issue. It appears to be working fine now and they're getting logs coming in nicely.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...