Splunk AWS Add-on : Ingestion of AWS Cloudtrail data in Splunk

แชร์
ฝัง
  • เผยแพร่เมื่อ 16 ก.ย. 2024

ความคิดเห็น • 35

  • @Harmanskardon
    @Harmanskardon 4 ปีที่แล้ว +3

    Thanks a lot for sharing this knowledge on youtube. You share the best Splunk tutorial videos which are much better than any other tutorials I have viewed, big fan sir

  • @viciouz25
    @viciouz25 ปีที่แล้ว

    Just one of the those videos I needed to help me understand Splunk integration to AWS. Thanks for the detail explanation. Would be checking from this channel. Great job!

  • @roopatvs91
    @roopatvs91 4 ปีที่แล้ว +1

    Your videos is very helpful especially for splunk developers.... ☺️☺️

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว +1

      Thank you 🙏

  • @dhanasekark7187
    @dhanasekark7187 3 ปีที่แล้ว

    Thanks Sir ...Very Useful.....
    1000 Times Thanks Again

  • @guddytech1454
    @guddytech1454 9 หลายเดือนก่อน

    Thanks a lot. This was really helpful

  • @JaeVoris
    @JaeVoris 2 ปีที่แล้ว

    this video is great, I finally got it working on Splunk 8.2. Could you create a very in depth troubleshooting series?

  • @valishaik9209
    @valishaik9209 4 ปีที่แล้ว

    Nice video, thank you sir.

  • @vikassingh4320
    @vikassingh4320 4 ปีที่แล้ว

    As usual The Best..

  • @saby826
    @saby826 4 ปีที่แล้ว

    Awesome video Sid da

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Thank you bhai :)

  • @rcavalcantijunior
    @rcavalcantijunior 3 ปีที่แล้ว

    Many thanks for sharing. Do you have one explaining how to configure cloud watch events? tks

  • @kalebzewengel4883
    @kalebzewengel4883 2 ปีที่แล้ว

    Hi Sid, your videos and step-by-step procedures are helpful. How may I contact you personally? Thx

  • @sagarbarai
    @sagarbarai ปีที่แล้ว

    Wondering if splunk supports oidc Auth for aws ? So that I don’t have to worry about access key and secret access key.

  • @GregoryBaskincom
    @GregoryBaskincom 3 ปีที่แล้ว

    Where do the indexes come from that are pre-populated in the app? Is it reading what's on the indexers?

  • @gnanaraja5277
    @gnanaraja5277 3 ปีที่แล้ว

    Hi Sid, thanks for the tutorial. Very much useful. Can you tell me what is the advantage of taking the SNS and SQS method over using the S3 bucket

    • @splunk_ml
      @splunk_ml  3 ปีที่แล้ว +1

      I think S3 will be useful when you have multiple AWS region cloudtrail data.If you have multiple AWS regions from which you want to gather CloudTrail data, the Amazon Web Services best practice is that you configure a trail that applies to all regions in the AWS partition in which you are working. You can then set up one CloudTrail input to collect data from the centralized S3 bucket where log files from all the regions are stored.
      In this video I just discussed the basic way of ingesting cloudtrail data. In future I will be covering S3 as well.

  • @Srini_Eyes
    @Srini_Eyes 4 ปีที่แล้ว

    Pretty Good Step-by-Step process. Quick question. I have an AWS environment with CloudTrail and CloudWatch Enabled. I can use this process and steps to ingest CloudTrail logs into Splunk. How about ingest CloudWatch logs into Splunk. What is the process? . Also, where do i install the Splunk Add-On for AWS installer. On a EC2 Linux instance in my AWS or on a On-Prem Windows/Linux server? My Splunk setup is currently on a Azure environment . I need to take the logs from AWS into the Splunk in Azure

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว +1

      For cloudwatch it will be similar, please have a look at the below link,
      docs.splunk.com/Documentation/AddOns/released/AWS/CloudWatchLogs
      You need to install this addon in your splunk environment, on Heavy forwader to be specific.

  • @himaninegi6002
    @himaninegi6002 2 ปีที่แล้ว

    Hi I'm using sqs based S3 method and my hf is using proxy setup .
    Getting error sns signature validation failed

  • @ravib6889
    @ravib6889 2 ปีที่แล้ว

    How to restrict access to S3 Bucket only to splunk cloud instance so that no one else can access it?

  • @rameshmedari2279
    @rameshmedari2279 3 ปีที่แล้ว

    how can we add the ec2 server logs to splunk

  • @Lakshyasrivastava-sz7tw
    @Lakshyasrivastava-sz7tw 2 ปีที่แล้ว

    hello sir i searches out for one policy containing permission for all inputs its not showing in the docs i think splunk docs is updated so kindly give path for that

    • @TurboBailey
      @TurboBailey 2 ปีที่แล้ว

      It looks like splunk have removed that page from the documentation - I have just experienced this very same issue - docs.splunk.com/Documentation/AddOns/latest/AWS/Permissions

  • @divyasetia12
    @divyasetia12 4 ปีที่แล้ว

    Hi Sir..when i installed this addon on splunk only the loading process is going on..its taking too much time and after that also didn’t show the tabs inputs ,configuration..what needs to be done then? Pls help

    • @divyasetia12
      @divyasetia12 4 ปีที่แล้ว

      And my splunk instance is also 8.0.3 and as this add on not showing any of its tab my splunk instance is also going down bcz of that

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Hi Divya,
      What is the version of the add-on you downloaded? For Splunk 8 it needs to be version 5 and above.

  • @ramchavva6189
    @ramchavva6189 3 ปีที่แล้ว

    need s3 storage to splunk integration video

  • @sujoykr4344
    @sujoykr4344 3 ปีที่แล้ว

    I want to get data from AWS RDS (mysql) to phantom. Can someone help me with this.

    • @splunk_ml
      @splunk_ml  3 ปีที่แล้ว

      You can index the RDS data in Splunk, then Forward it to Phantom using Splunk Phantom Add-on,
      community.splunk.com/t5/Archive/AWS-Database-logs-to-Splunk/m-p/430343
      th-cam.com/video/K2VfKolT6F4/w-d-xo.html
      th-cam.com/video/8u4Uqu8e10c/w-d-xo.html
      th-cam.com/video/FiqvoPTQfdw/w-d-xo.html

  • @elliotriegner1682
    @elliotriegner1682 4 ปีที่แล้ว

    I have followed all steps through two times and no events have indexed

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Can you see in _internal index... If any errors are showing up.

  • @rasikmhetre7770
    @rasikmhetre7770 2 ปีที่แล้ว

    how do I configure Splunk add on AWS on the indexer cluster, and i don't have WebUI open on indexers. I am getting errors in spite of giving correct details in inputs.conf, passwords.conf.
    splunklib.binding.HTTPError: HTTP 500 Internal Server Error -- b'{"messages":[{"type":"ERROR","text":"Cannot call handler \'splunk_ta_aws_settings_proxy\' due to missing script \'aws_proxy_settings_rh.py\'."}]}'
    2022-06-19 20:29:38,885 level=INFO pid=30634 tid=MainThread logger=splunksdc.collector pos=collector.py:run:270 | | message="Modular input exited."