Splunk® App for AWS (Legacy)

Release Notes

Acrobat logo Download manual as PDF


On July 15, 2022, the Splunk App for AWS will reach its end of life (EOL). After this date, Splunk will no longer maintain or develop this product. Splunk App for AWS is used for both IT monitoring and security use cases because it provides dashboards for both ITOps and security teams. The IT monitoring functionality in Splunk App for AWS is migrating to a content pack in Data Integrations called the Content Pack for Amazon Web Services Dashboards and Reports. The security use case functionality in Splunk App for AWS is migrating to the new Splunk App for AWS Security Dashboards. For more about migration options, see this community post.
This documentation does not apply to the most recent version of Splunk® App for AWS (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Known issues for the Splunk App for AWS

For known issues relevant to accounts, input configuration, and knowledge management, see also Known issues for the Splunk Add-on for Amazon Web Services.

Date filed Defect number Description
2016-05-24 AWSAPP-957
Historical detailed billing data does not include items that lack an Operation field, so totals do not include one-time costs
2016-05-09 AWSAPP-910
Lookup file unauthorized_errorCode.csv is outdated, causing incorrect unauthorized event counts in Security Overview and IAM Activity dashboards
2016-05-05 AWSAPP-891
App dashboard cannot find data in custom indexes specified via the add-on rather than the app
Workaround: Manually add your custom indexes to the index macros in the app, as described in http://docs.splunk.com/Documentation/AWS/4.2.0/Installation/Macros
2016-05-04 AWSAPP-888
Monthly Billing report is not handled properly due to timezone issue.
2016-05-03 AWSAPP-881
Total number of IAM user/group/policies is not correct
2016-05-02 AWSAPP-878
KVStore usage is growing to a noticeable size
2016-04-29 AWSAPP-873
Proxy does not work if heavy forwarder and search head need to use different proxy settings
Workaround: Configure your accounts and inputs using the Splunk Add-on for AWS and do not use the app's Configure tab.
2016-04-25 AWSAPP-827
BotoClientError: When using SigV4, you must specify a 'host' parameter.
2016-04-25 AWSAPP-821
Performance issue to load services in CloudWatch Create page
2016-04-24 AWSAPP-817
SPL used to extract tags is not optimized for best performance.
2016-04-24 AWSAPP-810
Enhancement: Instances name disappear after switching region in Individual EC2 instance dashboard
2016-04-20 AWSAPP-800
Performance issue: Long load time and difficult to choose specified item for in Folder/File name field in Create Page of S3 input
2016-04-08 AWSAPP-769
Historical detailed billing shows inaccurate total
2016-03-24 AWSAPP-735
Metadata doesn't support customized index
2016-03-08 AWSAPP-701
App should warn user if some of the S3 billing files in the target bucket will not be ingested
2016-03-07 AWSAPP-699
Wildcard option should be removed if user specifies customized option in CloudWatch input
2016-03-06 AWSAPP-698
Historical detailed billing data in China Region cannot be displayed because data does not have a field named 'BlendedCost'
2016-03-03 AWSAPP-695
Can't select dimensions by storage type when creating a CloudWatch input for S3
2016-02-29 AWSAPP-689
The estimated file size shown on the app's Billing input configuration screen is incorrect
2016-02-29 AWSAPP-688
App writes an incorrect data input file with multiple bucket names specified
2016-02-23 AWSAPP-678
Performance issue for Historical Billing - "Cost by Account" and "Month over Month Comparison"
2016-02-19 AWSAPP-673
Create account should be disabled in Metadata configure page to avoid confusion
2016-02-19 AWSAPP-672
When dashboard panels depend on data from a data source that is not collected, they show 0 but should instead show N/A.
2016-02-11 AWSAPP-660
Warning message on dashboards should take into account inputs configured through add-on directly on forwarders
Workaround: Workaround: Open each of your inputs from the app's Configure page and re-save them.
2016-01-22 AWSAPP-608
UI blocks user from creating multiple billing inputs with same account against same bucket
2016-01-19 AWSAPP-598
Topology bottom has black area in full screen.
2016-01-13 AWSAPP-568
AWS lookups aren't populated when the add-on is on a separate instance than the app.
2015-12-24 AWSAPP-527
AWS doesn't provide detail sourceIPAddress so that Notable CloudTrail Activity by Origin panel cannot display
2015-11-19 AWSAPP-450
Tags filter does not support drill-down to search result
2015-09-09 AWSAPP-385
Selecting all regions and all services in CloudWatch input results in some invalid tasks.
2015-08-27 AWSAPP-365
Old checkpointer will be invalid if user delete input and add it back
2015-08-24 AWSAPP-353
Old data input with different customized setting will still be merged together
2015-08-20 AWSAPP-348
Old Cloudwatch data can't be shown in App after upgrade TA
2015-08-20 AWSAPP-344
The list of account id filter of every page should come from config data but not aws account configured on that search head
Workaround: Workaround: In a complex distributed environment, do not use the remote target connection script to link individual search heads to individual forwarders.
2015-08-18 AWSAPP-302
VPC Flow Logs - Traffic Analysis dashboard shows weird charts for low-volume VPC flow data
2015-08-13 AWSAPP-244
UI Enhancement: Use combo box for user to enter share S3 bucket for billing
2015-07-31 AWSAPP-159
VPC Flow Log log group selection should support multiselect
Last modified on 24 May, 2016
PREVIOUS
Fixed issues for the Splunk App for AWS
  NEXT
Credits for the Splunk App for AWS

This documentation applies to the following versions of Splunk® App for AWS (Legacy): 4.1.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters