Splunk® Content Packs for ITSI and IT Essentials Work

Splunk Content Packs for ITSI and IT Essentials Work

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

About the Content Pack for Amazon Web Services Dashboards and Reports

The Content Pack for Amazon Web Services (AWS) Dashboards and Reports gives you critical operational insight into your AWS accounts.

The content pack includes these components:

  • A pre-built knowledge base of dashboards and reports that deliver real-time visibility into your environment.
  • Insights dashboards that display detected problems in your AWS environment and provide best practices to help you optimize AWS resources, including Elastic IP addresses (EIP), Elastic Load Balancing ELB), and Elastic Block Store (EBS).
  • Dashboards for the Configure AWS Billing Tag, Timeline, Topology, Usage, Insights, Detailed Billing, and Billing Cost and Usage Reports (CUR) features.
  • Knowledge objects that populate the dashboards present in the content pack.

Installation

The Splunk App for Content Packs library contains the Content Pack for Amazon Web Services Dashboards and Reports. For installation instructions, see Install and configure the Content Pack for Amazon Web Services Dashboards and Reports.

The Content Pack for Amazon Web Services Dashboards and Reports and the Splunk App for AWS contain identical knowledge objects that cause a conflict when installed on the same search head deployment. To avoid conflict, don't install both apps on the same search head.

Deployment requirements

Refer to the following table to ensure you are running the correct version of the content pack, ITSI, IT Essentials Work, and the Splunk Add-on for AWS:

Content pack version ITSI version IT Essentials Work version Splunk Add-on for AWS version
1.1.0 4.9.0 and higher 4.9.0 and higher 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4
1.0.0 4.9.0 and higher 4.9.0 and higher 5.0.0, 5.0.1, 5.0.2, 5.0.3

Splunk Add-on for Amazon Web Services compatibility

The Content Pack for Amazon Web Services Dashboards and Reports relies on the Splunk Add-on for Amazon Web Services (AWS) version 4.6.0 or higher. You must install both the Splunk Add-on for AWS and the content pack for the content pack to function.

Refer to the following table to ensure you are running the correct version of the Splunk Enterprise, Python, and the Splunk Add-on for AWS:

Splunk Enterprise version Python version Add-on version
8.0.0 Python 3 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4
7.3, 8.0.0 Python 2 4.6.1

The Addon Metadata - Summarize AWS Inputs is a saved search that aggregates input data into the summary index. This saved search is included with the Splunk Add-on for AWS but disabled by default. You can enable this saved search in the add-on settings.

For information about installing the Splunk Add-on for AWS, see Installation overview for the Splunk Add-on for AWS. Use the add-on setup and configuration user interface to link to your AWS account and configure data collection.

Migrate from Splunk App for AWS to the Content Pack for Amazon Web Services Dashboards and Reports

If you are using the Splunk App for AWS and want to migrate to Content Pack for Amazon Web Services Dashboards and Reports, go to Migrate from Splunk App for AWS to Content Pack for Amazon Web Services Dashboards and Reports.

On January 5, 2022, the Splunk App for AWS will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to the Content Pack for Amazon Web Services Dashboards and Reports.

AWS region limitations

The Content Pack for Amazon Web Services Dashboards and Reports relies on the Splunk Add-on for Amazon Web Services. The Splunk Add-on for Amazon Web Services supports all regions offered by AWS.

If you are in the AWS China region, the add-on supports only the services that AWS supports in that region. The China region does not support Config Rules, Inspector, CloudWatch Logs, or CloudFront services, nor does it offer CloudWatch metrics for ELB logs. For an up-to-date list of what products and services are supported in this region, see the AWS documentation at https://www.amazonaws.cn/en/products/.

If you are in the AWS GovCloud region, the add-on supports only the services that AWS supports in that region. The GovCloud region does not support Config Rules or Inspector at this time. For an up-to-date list of what services and endpoints are supported in this region, see the AWS documentation at https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/using-services.html.

Additional resources

Last modified on 21 October, 2021
PREVIOUS
Configure the Content Pack for Alert Routing
  NEXT
Release notes for the Content Pack for Amazon Web Services Dashboards and Reports

This documentation applies to the following versions of Splunk® Content Packs for ITSI and IT Essentials Work: current


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters