Splunk is populating with all of the logs from aws, but GET events like GetBucketPolicy, GetBucketAcls, etc. aren't populating with the information they are "GETting." Here's an example of what my queries look like:
requestParameters: {
Host: Blah.us-east-1.amazonaws.com
acl:
bucketName: Blah
}
The SET events seem to have those fields filled out though. But all the GET ones have a blank in the requestParameters. I wasn't able to find anything on this in the docs for the addon.