Troubleshoot AWS CloudTrail data ingestion
Troubleshoot the AWS CloudTrail data ingestion process.
CloudTrail logs are not enabled by default.
CloudTrail log data cannot be found
AWS CloudTrail log data cannot be found.
Cause
AWS CloudTrail is not enabled or is not configured correctly, or Splunk HEC is not configured correctly.
Solution
- In AWS, navigate to CloudTrail in the AWS region selected when the data input was created in Data Manager.
- If CloudWatch logging is not enabled for that CloudTrail, enable sending CloudTrail logs to CloudWatch. See the Sending events to CloudWatch Logs topic in the AWS documentation.
- Navigate to Data Management. Click the Data Input Details tab, and go to the Account Establishment Details section. If a stack is in FAILED state, refer to Deployment Status: Failed for more troubleshooting steps.
- Verify the Splunk HTTP Event Collector (HEC) configuration. See the HTTP Event Collector (HEC) configuration reference topic in this manual to troubleshoot Splunk software-side HEC configurations.
- In AWS, navigate to Data Ingestion through Lambda functions to troubleshoot the Lambda function.
- If the HEC token is present and enabled in the Splunk software, in AWS, navigate to Kinesis > Delivery streams.
- Select
SplunkDMCloudTrailDeliveryStream
and verify that the status is active. - Click on the Configuration section and verify the source record transformation is enabled with
SplunkDMCloudWatchLogProcessor
as the Lambda function. - Navigate to CloudTrail, select the trail and make a note of the CloudWatch log group.
- Navigate to the CloudWatch log group noted in the previous step.
- Under Subscription filters, the Destination ARN should target to the Kinesis firehose delivery stream.
- If any AWS resource is missing or misconfigured, delete the data input in Data Manager and recreate it.
- If the configuration is correct and your data still cannot be found, Contact Splunk Support.
Troubleshoot the AWS Deployment Status | Troubleshoot AWS SecurityHub data ingestion |
This documentation applies to the following versions of Data Manager: 1.11.0
Feedback submitted, thanks!