All Apps and Add-ons

What is Splunk App for AWS and how can I configure it

bjyoti
Engager

Hi All,

I am exporing splunk these days. I have installed splunk enterprize on my linux machine. I want to monitor my AWS account logs on splunk. For this I have want to install Splunk app for AWS.

Here are my queries :

  1. What are the prerequisites for the installing and configuring the splunk app.
  2. Is it required to have cloud trail in my aws account.
  3. which file should I edit to enter my aws keys to review the logs ?
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The documentation with the app is pretty straightforward. To summarize them, you need Splunk, and yes, you need to configure CloudTrail in AWS. You don't need to edit config files (though you can if you want and are familiar with it) but you can just configure a new CloudTrail input. Most people will need only one, but if you're logging different regions to different places, or have multiple accounts, you can configure multiple CloudTrail inputs.

bjyoti
Engager

I have configured the cloud trail but getting error : std::bad_alloc

0 Karma

bjyoti
Engager

I have configured cloud trail on my AWS account but I cant see any data in my Splunk App for AWS. DO I need to update my aws keys in any of the file in splunk app ???Please help

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...