Splunk® App for AWS

Release Notes

Download manual as PDF

Download topic as PDF

The Splunk App for AWS Release Notes

These release notes apply to the Splunk App for AWS version 5.2.0.

For compatibility information, see Hardware and software requirements for the Splunk App for AWS.

New features

New feature or enhancement Description
AWS Cost and Usage Reports (CUR) for billing data The Splunk App for AWS supports AWS CUR to analyze billing data for your AWS account.


You can select to populate these billing dashboards and panels with AWS Cost and Usage Reports (CUR):

  • Budget Planner dashboard
  • Historical Monthly Bills dashboard
  • Historical Detailed Bills dashboard
  • Capacity Planner dashboard
  • Reserved Instance Planner dashboard
  • Reserved Instance Inventory (RI Utilization by Family in Last Month panel)
  • Topology dashboard (Billing layer)
  • Reserved Instance Planner Detail dashboard

If you do not have access to CUR, you can continue using Detailed Billing Reports (DBR) to monitor billing data.

When you set up a CUR input and start populating billing dashboards with CUR data, you can disable DBR inputs from the Splunk Add-on for Amazon Web Services. When you start populating billing dashboards with CUR data, the app no longer uses DBR data. If you want to view DBR data again, switch the billing report type.

To start monitoring CUR data in the Splunk App for AWS, see Specify the type of AWS billing data to monitor.

New knowledge objects The new knowledge objects support AWS CUR to analyze billing data for your AWS account.


There are two new saved searches:

  • Billing CUR: Billing Reports AssemblyId Generator
  • Billing CUR: Topology Billing Metric Generator

For more information about the saved searches, see Saved searches for the Splunk App for AWS. There are two new data models:

  • Detailed Billing CUR
  • Instance Hour CUR

For more information about data models, see Data models for the Splunk App for AWS. There is one new macro:

  • aws-billing-index-cur

For more information about macros, see Macros for the Splunk App for AWS.

Fixed issues

Date resolved Issue number Description
2019-05-29 AWSAPP-2032 The EC2 Insights Dashboard does not populate even when the required sourcetypes are available.
2019-05-27 AWSAPP-2127 A terminated resource displays in the Topology view.
2019-03-26 AWSAPP-2056 The Capacity Planner does not display data if the app is installed on Splunk Enterprise version 7.2.x.

For fixed issues relevant to accounts, inputs configuration, and knowledge management, see the Fixed issues for the Splunk Add-on for Amazon Web Services.

Known issues

Date filed Issue number Description
2019-08-21 AWSAPP-2156 Capacity Planer: Data mismatch between Dashboard panels and AWS Console
2019-05-17 AWSAPP-2124 Billing CUR: The dashboard panels take a longer time to populate with the Billing (Cost and Usage Report) billing report type than the Billing (Legacy) billing report type.
2019-05-15 AWSAPP-2119 Capacity Planner (CUR): Value mismatch between panel data of Billing Legacy and Billing CUR.
2019-05-10 AWSAPP-2112 Historical Monthly Bills: Value mismatch in "Cost by Service" panel
2019-05-07 AWSAPP-2107 Billing CUR: Account Name is not visible in any of the dashboards or panels that use Billing (Cost and Usage Report) data.

For known issues relevant to accounts, inputs configuration, and knowledge management, see also Known issues for the Splunk Add-on for Amazon Web Services.

See also

To get started with the app, see the Installation and Configuration Manual.

For upgrade requirements, see Upgrade the Splunk App for AWS.

  NEXT
Credits for the Splunk App for AWS

This documentation applies to the following versions of Splunk® App for AWS: 5.2.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters