Splunk® App for AWS (Legacy)

Installation and Configuration Manual

Acrobat logo Download manual as PDF


On July 15, 2022, the Splunk App for AWS will reach its end of life (EOL). After this date, Splunk will no longer maintain or develop this product. Splunk App for AWS is used for both IT monitoring and security use cases because it provides dashboards for both ITOps and security teams. The IT monitoring functionality in Splunk App for AWS is migrating to a content pack in Data Integrations called the Content Pack for Amazon Web Services Dashboards and Reports. The security use case functionality in Splunk App for AWS is migrating to the new Splunk App for AWS Security Dashboards. For more about migration options, see this community post.
This documentation does not apply to the most recent version of Splunk® App for AWS (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Hardware and software requirements for the Splunk App for AWS

Splunk platform requirements

The Splunk App for AWS runs on the following Splunk platforms:

Because this app runs on the Splunk platform, all of the system requirements apply for the Splunk software that you use to run this app.

  • If you plan to run this app in Splunk Cloud only, there are no additional requirements.
  • If you plan to manage on-premises heavy forwarders to get data in to Splunk Cloud, see System Requirements in the Installation Manual in the Splunk Enterprise documentation, which includes information about forwarders.
  • If you plan to run this app in an on-premises deployment of the Splunk platform, see System Requirements in the Installation Manual in the Splunk Enterprise documentation.
  • If you plan to run this app in a self-managed AWS instance, there are no additional requirements. Refer to the Virtual hardware information for sizing considerations specific to AWS.

Splunk Add-on for Amazon Web Services

The Splunk App for AWS relies on the Splunk Add-on for Amazon Web Services version 4.1.2 or later. Both the add-on and the app need to be installed for the app to function. For information about installing the Splunk Add-on for AWS, refer to Install the Splunk Add-on for AWS in the Splunk Add-on for AWS manual.

Python for Scientific Computing

The Recommendations Service feature of this release depends on the Python for Scientific Computing app version 1.1, available on Splunkbase. Install the app appropriate for your environment on all Splunk search heads running the Splunk App for AWS.

Note: Splunk Light does not support the Recommendations Service feature and therefore does not require the Python for Scientific Computing app as a prerequisite.

AWS account requirements

To install and set up the app, you must have a valid AWS account with sufficient permissions to configure the AWS services from which you want to collect data. You must also have permission to create IAM roles and users so that you can set up accounts with the appropriate permissions that the app can use to collect data from your AWS services.

For more information about the permissions required by the account used in the app to perform data collection, see Configure your AWS permissions for the Splunk App for AWS.

AWS region limitations

The Splunk Add-on for AWS supports all regions offered by AWS.

If you are in the AWS China region, the add-on only supports the services that AWS supports in that region. The China region does not support Config Rules, Inspector, CloudWatch Logs, or CloudFront services, nor does it offer CloudWatch metrics for ELB logs. For an up-to-date list of what products and services are supported in this region, see http://www.amazonaws.cn/en/products/.

If you are in the AWS GovCloud region, the add-on only supports the services that AWS supports in that region. The GovCloud region does not support Config Rules, or Inspector at this time. For an up-to-date list of what services and endpoints are supported in this region, see the AWS documentation: http://docs.aws.amazon.com/govcloud-us/latest/UserGuide/using-services.html.

Last modified on 24 November, 2016
PREVIOUS
What data the Splunk App for AWS collects
  NEXT
Plan your deployment of the Splunk App for AWS

This documentation applies to the following versions of Splunk® App for AWS (Legacy): 5.0.0, 5.0.1, 5.0.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters