I believe this is an issue with the way some of the AWS Dashboard searches are written. The tags at the beginning of the searches seem to only denote sourcetype. This can cause a searching issue, because by default your account does not search any custom indexes.
i.e.:
If I were to search:
sourcetype=aws:billing
I would most likely get 0 results.
This is because Splunk translates the above search to:
index = <Indexes searched by default> sourcetype=aws:billing
However, if I were to search:
index=aws sourcetype=aws:billing
I would see results.
There are a couple ways to test this:
Go to access controls, and add your AWS/Billing index to the "Indexes searched by default"
Open up one of the dashboard panels in a search window and preface the search with "index = Your AWS Billing Index"
... View more