Splunk® App for AWS (Legacy)

User Manual

On July 15, 2022, the Splunk App for AWS will reach its end of life (EOL). After this date, Splunk will no longer maintain or develop this product. Splunk App for AWS is used for both IT monitoring and security use cases because it provides dashboards for both ITOps and security teams. The IT monitoring functionality in Splunk App for AWS is migrating to a content pack in Data Integrations called the Content Pack for Amazon Web Services Dashboards and Reports. The security use case functionality in Splunk App for AWS is migrating to the new Splunk App for AWS Security Dashboards. For more about migration options, see this community post.
This documentation does not apply to the most recent version of Splunk® App for AWS (Legacy). For documentation on the most recent version, go to the latest release.

Filter dashboards by tags in the Splunk App for AWS

The Splunk App for AWS dashboards allow you to filter content by the tags you have defined in Amazon Web Services. Tags are custom metadata that you can use to identify and organize your AWS resources. Each of your resources can have up to ten tags, each of which consists of a key and an optional value. See the Reference section below for more information about defining tags in AWS.

Use the tags filter on a dashboard

To use the tags filter, navigate to any Splunk App for AWS dashboard that supports the filter, such as the Overview dashboard. Some dashboards do not include a tags filter, often because the data in that dashboard is not relevant to tags.

1. Click in the Tags field. The app displays all the keys you have defined in AWS.

2. Browse to or search for the key you want.

3. The app displays the key you have selected along with some options for values. You can:

  • select is empty to match keys without values.
  • select a value from the list
  • enter any string, then select Contains: to match all values that contain this string

4. To add an additional tag to the filter, repeat steps 1 - 3. Tags follow AND logic, so the dashboard displays only the data that matches all tags in the filter.

Select tags for your Historical Detailed Billing and Capacity Planner dashboards

Both the Historical Detailed Billing and Capacity Planner dashboards rely on data from your Detailed billing reports with resources and tags. These reports can be very large, affecting the performance of your dashboards. For this reason, all custom tags are disabled by default.

A Splunk platform administrator can select the custom tags that should appear in your tag filters for these dashboards on the app's Configure tab. When you initially select tags and each time you change your selections, your Capacity Planner and Historical Detailed Billing dashboards will be unavailable while their underlying data models are rebuilt to reflect your tag selections. The time required for the data models to rebuild depends on the volume of your billing data.

You can check on the status of the data models by going to Settings > Data models and expanding the rows for the the Detailed Billing and Instance Hour data models.

The tags that you select to use on these two dashboards are available both as standard filters at the top of the dashboard and in special "Group By" filters. In the Cost Analysis section of the Historical Detailed Bills dashboard, you have the options to filter your data by Service and Operation, and then further group the results by either the Product Name, Availability Zone, Operation, or any custom tags that you have selected. Similarly, on the Capacity Planner dashboard, you can group by Instance Type, Reservation, Availability Zone, or any custom tags you have selected.

Note: In the Tags drop-down menu, the app replaces any special characters in your tags with underscores and truncates tag names to the first 32 characters. When searching for a tag, modify your search to match.

Reference

For more information about how to create tags in AWS, see http://docs.aws.amazon.com/awsconsolehelpdocs/latest/gsg/tag-editor.html. You can also read the AWS documentation for specific services for more detailed information and best practices for how to apply tags to your resources.

For example, see http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html for information on tagging EC2 resources.

Last modified on 21 August, 2017
Overview of the dashboards in the Splunk App for AWS   Topology dashboard reference for the Splunk App for AWS

This documentation applies to the following versions of Splunk® App for AWS (Legacy): 4.2.0, 4.2.1, 5.0.0, 5.0.1, 5.0.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters