All Apps and Add-ons

What is the proper configuration for AWS SQS/SNS in a consolidated account environment?

larry_youngquis
New Member

We have multiple sub-accounts that aggregate their cloudtrail data into a single S3 bucket stored at the master account level.

What, if any, SQS and SNS configurations need to be done at the sub-account level? Or, is it only defined for the master account?

0 Karma

scpack
New Member

Hey Larry,

I doing this same thing, Aggregating CloudTrail for ingest via S3. Rather than using the CloudTrail input type with the SQS queue name I'm using the S3 input on the bucket. Simplifies deployment a lot, but you have to keep in mind that the events will only be as up to date as your S3 polling interval.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

You'll need a modular input instance per queue. I don't think the bucket aggregation will matter, though it might make permissions more entertaining.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

This answer was assuming that you would manually aggregate several CloudTrail accounts so that you get a separate XML file from each account's events. However, if you've linked the accounts to each other you'll actually get a single XML file per period with multiple accounts and multiple events in it. Add-on for AWS version 1.1.1 was just posted Thursday and supports this scenario.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...