On July 15, 2022, the Splunk App for AWS will reach its end of life (EOL). After this date, Splunk will no longer maintain or develop this product. Splunk App for AWS is used for both IT monitoring and security use cases because it provides dashboards for both ITOps and security teams. The IT monitoring functionality in Splunk App for AWS is migrating to a content pack in Data Integrations called the Content Pack for Amazon Web Services Dashboards and Reports. The security use case functionality in Splunk App for AWS is migrating to the new Splunk App for AWS Security Dashboards. For more about migration options, see this community post.
This documentation does not apply to the most recent version of Splunk® App for AWS (Legacy).
For documentation on the most recent version, go to the latest release.
Download topic as PDF
Known issues for the Splunk App for AWS
For known issues relevant to accounts, input configuration, and knowledge management, see also Known issues for the Splunk Add-on for Amazon Web Services.
Date filed | Defect number | Description |
---|---|---|
2016-05-24 | AWSAPP-957 |
Historical detailed billing data does not include items that lack an Operation field, so totals do not include one-time costs |
2016-05-09 | AWSAPP-910 |
Lookup file unauthorized_errorCode.csv is outdated, causing incorrect unauthorized event counts in Security Overview and IAM Activity dashboards |
2016-05-05 | AWSAPP-891 |
App dashboard cannot find data in custom indexes specified via the add-on rather than the app Workaround: Manually add your custom indexes to the index macros in the app, as described in http://docs.splunk.com/Documentation/AWS/4.2.0/Installation/Macros |
2016-05-04 | AWSAPP-888 |
Monthly Billing report is not handled properly due to timezone issue. |
2016-05-03 | AWSAPP-881 |
Total number of IAM user/group/policies is not correct |
2016-05-02 | AWSAPP-878 |
KVStore usage is growing to a noticeable size |
2016-04-29 | AWSAPP-873 |
Proxy does not work if heavy forwarder and search head need to use different proxy settings Workaround: Configure your accounts and inputs using the Splunk Add-on for AWS and do not use the app's Configure tab. |
2016-04-25 | AWSAPP-827 |
BotoClientError: When using SigV4, you must specify a 'host' parameter. |
2016-04-25 | AWSAPP-821 |
Performance issue to load services in CloudWatch Create page |
2016-04-24 | AWSAPP-817 |
SPL used to extract tags is not optimized for best performance. |
2016-04-24 | AWSAPP-810 |
Enhancement: Instances name disappear after switching region in Individual EC2 instance dashboard |
2016-04-20 | AWSAPP-800 |
Performance issue: Long load time and difficult to choose specified item for in Folder/File name field in Create Page of S3 input |
2016-04-08 | AWSAPP-769 |
Historical detailed billing shows inaccurate total |
2016-03-24 | AWSAPP-735 |
Metadata doesn't support customized index |
2016-03-08 | AWSAPP-701 |
App should warn user if some of the S3 billing files in the target bucket will not be ingested |
2016-03-07 | AWSAPP-699 |
Wildcard option should be removed if user specifies customized option in CloudWatch input |
2016-03-06 | AWSAPP-698 |
Historical detailed billing data in China Region cannot be displayed because data does not have a field named 'BlendedCost' |
2016-03-03 | AWSAPP-695 |
Can't select dimensions by storage type when creating a CloudWatch input for S3 |
2016-02-29 | AWSAPP-689 |
The estimated file size shown on the app's Billing input configuration screen is incorrect |
2016-02-29 | AWSAPP-688 |
App writes an incorrect data input file with multiple bucket names specified |
2016-02-23 | AWSAPP-678 |
Performance issue for Historical Billing - "Cost by Account" and "Month over Month Comparison" |
2016-02-19 | AWSAPP-673 |
Create account should be disabled in Metadata configure page to avoid confusion |
2016-02-19 | AWSAPP-672 |
When dashboard panels depend on data from a data source that is not collected, they show 0 but should instead show N/A. |
2016-02-11 | AWSAPP-660 |
Warning message on dashboards should take into account inputs configured through add-on directly on forwarders Workaround: Workaround: Open each of your inputs from the app's Configure page and re-save them. |
2016-01-22 | AWSAPP-608 |
UI blocks user from creating multiple billing inputs with same account against same bucket |
2016-01-19 | AWSAPP-598 |
Topology bottom has black area in full screen. |
2016-01-13 | AWSAPP-568 |
AWS lookups aren't populated when the add-on is on a separate instance than the app. |
2015-12-24 | AWSAPP-527 |
AWS doesn't provide detail sourceIPAddress so that Notable CloudTrail Activity by Origin panel cannot display |
2015-11-19 | AWSAPP-450 |
Tags filter does not support drill-down to search result |
2015-09-09 | AWSAPP-385 |
Selecting all regions and all services in CloudWatch input results in some invalid tasks. |
2015-08-27 | AWSAPP-365 |
Old checkpointer will be invalid if user delete input and add it back |
2015-08-24 | AWSAPP-353 |
Old data input with different customized setting will still be merged together |
2015-08-20 | AWSAPP-348 |
Old Cloudwatch data can't be shown in App after upgrade TA |
2015-08-20 | AWSAPP-344 |
The list of account id filter of every page should come from config data but not aws account configured on that search head Workaround: Workaround: In a complex distributed environment, do not use the remote target connection script to link individual search heads to individual forwarders. |
2015-08-18 | AWSAPP-302 |
VPC Flow Logs - Traffic Analysis dashboard shows weird charts for low-volume VPC flow data |
2015-08-13 | AWSAPP-244 |
UI Enhancement: Use combo box for user to enter share S3 bucket for billing |
2015-07-31 | AWSAPP-159 |
VPC Flow Log log group selection should support multiselect |
Last modified on 24 May, 2016
PREVIOUS Fixed issues for the Splunk App for AWS |
NEXT Credits for the Splunk App for AWS |
This documentation applies to the following versions of Splunk® App for AWS (Legacy): 4.1.1
Feedback submitted, thanks!