Hello,
Looked all over google and did not find a solution and Splunk support is not very responsive. I am hoping someone will give me a quick answer to this. I have a Search Head Cluster with three search instances. I deployed Splunk App for AWS Add-on via Deployer to all three search heads. I then created an IAM Role with all the permissions necessary using Splunk Documentation and attached the role to all three Search Head EC2 Instances on AWS. Logged back into each Search Head Instances and I only see the role auto-discovered on one of the Search Heads as oppose to all three. Is that by design or am I missing something? Thanks in advance for any answers to this.
I figured out what the answer was. My instances were not assuming IAM roles