About the Content Pack for Amazon Web Services Dashboards and Reports
The Content Pack for Amazon Web Services (AWS) Dashboards and Reports gives you critical operational insights into your AWS accounts.
The content pack includes these components:
- A pre-built dashboards and reports that deliver real-time visibility into your environment.
- Knowledge objects that populate the dashboards in the content pack.
- Four entity searches you can enable when you are ready to run them to import your AWS Cloud entities. See Enable entity searches.
- Four entity types with vital metrics that describe the overall performance of entities.
Installation
You can install the Content Pack for Amazon Web Services Dashboards and Reports after installing the Splunk App for Content Packs on the search head where you have installed ITSI or ITE Work. For installation instructions, see Install and configure the Content Pack for Amazon Web Services Dashboards and Reports.
The Content Pack for Amazon Web Services Dashboards and Reports and the Splunk App for AWS contain identical knowledge objects that cause a conflict when installed on the same search head deployment. To avoid conflict, don't install both apps on the same search head. See Migrate from the Splunk App for AWS to the Content Pack for Amazon Web Services Dashboards and Reports for steps to migrate.
Deployment requirements
Refer to the following table to ensure you are running the correct version of the content pack, ITSI, IT Essentials Work, and the Splunk Add-on for AWS.
Splunk Add-on for AWS v6.0.0 or later is not supported with the Content Pack for AWS Dashboards and Reports.
Content pack version | ITSI version | IT Essentials Work version | Splunk Add-on for AWS version |
---|---|---|---|
1.2.2 | 4.13.0 and higher | 4.13.0 and higher | 5.1.0, 5.2.0 |
1.2.1 | 4.11.0 and higher | 4.11.0 and higher | 5.0.4, 5.1.0, 5.2.0 |
1.2.0 | 4.11.0 and higher | 4.11.0 and higher | 5.0.4, 5.1.0, 5.2.0 |
1.1.1 | 4.9.0 and higher | 4.9.0 and higher | 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.1.0, 5.2.0 |
1.1.0 | 4.9.0 and higher | 4.9.0 and higher | 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4 |
1.0.0 | 4.9.0 and higher | 4.9.0 and higher | 5.0.0, 5.0.1, 5.0.2, 5.0.3 |
Splunk Add-on for Amazon Web Services compatibility
The Content Pack for Amazon Web Services Dashboards and Reports relies on the Splunk Add-on for Amazon Web Services (AWS) version 5.1.0 or higher. You must install both the Splunk Add-on for AWS and the content pack for the content pack to function.
Refer to the following table to ensure you are running the correct version of the Splunk Enterprise, Python, and the Splunk Add-on for AWS:
Splunk Enterprise version | Python version | Add-on version |
---|---|---|
8.1.x, 8.2.x, 9.0.0 | Python 3 | 5.0.4, 5.1.0, 5.2.0 |
8.0.0 | Python 3 | 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.1.0, 5.2.0 |
7.3, 8.0.0 | Python 2 | 4.6.1 |
The Addon Metadata - Summarize AWS Inputs is a saved search that aggregates input data into the summary index. This saved search is included with the Splunk Add-on for AWS but disabled by default. You can enable this saved search in the add-on settings.
For information about installing the Splunk Add-on for AWS, see Installation overview for the Splunk Add-on for AWS. Use the add-on setup and configuration user interface to link to your AWS account and configure data collection.
Migrate from Splunk App for AWS to the Content Pack for Amazon Web Services Dashboards and Reports
On January 5, 2022, the Splunk App for AWS will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to the Content Pack for Amazon Web Services Dashboards and Reports.
If you are using the Splunk App for AWS and want to migrate to Content Pack for Amazon Web Services Dashboards and Reports, go to Migrate from Splunk App for AWS to Content Pack for Amazon Web Services Dashboards and Reports.
AWS region limitations
The Content Pack for Amazon Web Services Dashboards and Reports relies on the Splunk Add-on for Amazon Web Services. The Splunk Add-on for Amazon Web Services supports all regions offered by AWS.
If you are in the AWS China region, the add-on supports only the services that AWS supports in that region. The China region does not support Config Rules, Inspector, CloudWatch Logs, or CloudFront services, nor does it offer CloudWatch metrics for ELB logs. For an up-to-date list of what products and services are supported in this region, see the AWS documentation at https://www.amazonaws.cn/en/products/.
If you are in the AWS GovCloud region, the add-on supports only the services that AWS supports in that region. The GovCloud region does not support Config Rules or Inspector at this time. For an up-to-date list of what services and endpoints are supported in this region, see the AWS documentation at https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/using-services.html.
Additional resources
- For the input types to configure each dashboard, see Dashboard reference for the Content Pack for AWS.
- For ITSI deployment planning guidelines, see Plan your ITSI deployment in the Splunk IT Service Intelligence Install and Upgrade Manual.
- For ITSI version compatibility with Splunk Enterprise versions, see Splunk products version compatibility matrix in the Splunk Version Compatibility Matrix manual.
Release notes for the Content Pack for Amazon Web Services Dashboards and Reports |
This documentation applies to the following versions of Content Pack for Amazon Web Services Dashboards and Reports: 1.2.2
Feedback submitted, thanks!