Splunk® Supported Add-ons

Splunk Add-on for Amazon Kinesis Firehose

Release history for the Splunk Add-on for Amazon Kinesis Firehose

Version 1.3.1

Version 1.3.1 of the Splunk Add-on for Amazon Kinesis Firehose was released on November 30, 2020.

Compatibility

Version 1.3.1 of the Splunk Add-on for Amazon Kinesis Firehose is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.1, 7.2, 7.3.x, 8.0.x
CIM 4.18 and later
Platforms Platform independent
Vendor Products Amazon Kinesis Firehose data, CloudWatch, VPC Flow Logs, AWS CloudTrail, GuardDuty, AWS Security Hub findings events

The Splunk Add-on for Amazon Kinesis Firehose uses different source types than the Amazon GuardDuty Add-on for Splunk. Because of this, the Splunk Add-on for Amazon Kinesis Firehose is incompatible with the Amazon GuardDuty Add-on for Splunk.

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

Version 1.3.1 of the Splunk Add-on for Amazon Kinesis Firehose contains the following new features:

  • Increased Alerts CIM data model compatibility.
  • Increased Change CIM data model compatibility.
  • Support for ingestion of AWS Security Hub findings events.

Fixed issues

Version 1.3.1 of the Splunk Add-on for Amazon Kinesis Firehose fixes the following, if any, issues.

Known issues

Version 1.3.1 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.

Third-party software attributions

Version 1.3.1 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.


Latest release

The latest version of the Splunk Add-on for Amazon Kinesis Firehose is version 1.3.1. See Release notes for the Splunk Add-on for Amazon Kinesis Firehose for the release notes of this latest version.

Version 1.2.2

Version 1.2.2 of the Splunk Add-on for Amazon Kinesis Firehose was released on July 23, 2020.

Compatibility

Version 1.2.2 of the Splunk Add-on for Amazon Kinesis Firehose is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.1, 7.2, 7.3.x, 8.0.x
CIM 4.16 and later
Platforms Platform independent
Vendor Products Amazon Kinesis Firehose data, CloudWatch, VPC Flow Logs, AWS CloudTrail, GuardDuty

The Splunk Add-on for Amazon Kinesis Firehose uses different source types than the Amazon GuardDuty Add-on for Splunk. Because of this, the Splunk Add-on for Amazon Kinesis Firehose is incompatible with the Amazon GuardDuty Add-on for Splunk.

New features

Version 1.2.2 of the Splunk Add-on for Amazon Kinesis Firehose contains the following new features:

  • Increased Network Traffic CIM data model compatibility.
  • Increased Change CIM data model compatibility.

Fixed issues

Version 1.2.2 of the Splunk Add-on for Amazon Kinesis Firehose fixes the following issues.


Date resolved Issue number Description
2020-07-10 ADDON-27592 Fixed inline comments issue in props.conf

Known issues

Version 1.2.2 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.


Third-party software attributions

Version 1.2.2 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.


Version 1.2.1

Version 1.2.1 of the Splunk Add-on for Amazon Kinesis Firehose was released on April 30, 2020.

Compatibility

Version 1.2.1 of the Splunk Add-on for Amazon Kinesis Firehose is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.1, 7.2, 7.3.x, 8.0.x
CIM 4.16 and later
Platforms Platform independent
Vendor Products Amazon Kinesis Firehose data, CloudWatch, VPC Flow Logs, AWS CloudTrail, GuardDuty

The Splunk Add-on for Amazon Kinesis Firehose uses different source types than the Amazon GuardDuty Add-on for Splunk. Because of this, the Splunk Add-on for Amazon Kinesis Firehose is incompatible with the Amazon GuardDuty Add-on for Splunk.

New features

Version 1.2.1 of the Splunk Add-on for Amazon Kinesis Firehose contains:

  • Improved Support for the Authentication CIM Model.

Fixed issues

Version 1.2.1 of the Splunk Add-on for Amazon Kinesis Firehose fixes the following issues.

Known issues

Version 1.2.1 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.

Third-party software attributions

Version 1.2.1 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.

Version 1.2.0

Version 1.2.0 of the Splunk Add-on for Amazon Kinesis Firehose was released on May 17, 2018.

Compatibility

Version 1.2.0 of the Splunk Add-on for Amazon Kinesis Firehose is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.6, 7.0, 7.1, 7.2
CIM 4.8 and later
Platforms Platform independent
Vendor Products Amazon Kinesis Firehose data, CloudWatch, VPC Flow Logs, AWS CloudTrail, GuardDuty

The Splunk Add-on for Amazon Kinesis Firehose uses different source types than the Amazon GuardDuty Add-on for Splunk. Because of this, the Splunk Add-on for Amazon Kinesis Firehose is incompatible with the Amazon GuardDuty Add-on for Splunk.

New features

Version 1.2.0 of the Splunk Add-on fixes bugs and adds support for the GuardDuty sourcetype.

Fixed issues

Version 1.2.0 of the Splunk Add-on for Amazon Kinesis Firehose fixes the following issues.


Date resolved Issue number Description
2018-04-25 ADDON-17577 Using the "generate sample findings" option in GuardDuty causes CloudWatch events to not be linebroken.
2018-04-25 ADDON-17576 Timestamp for VPC flow logs are based on record's arrival timestamp and are inaccurate

Known issues

Version 1.2.0 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.


Third-party software attributions

Version 1.2.0 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.


Version 1.1.1

Version 1.1.1 of the Splunk Add-on for Amazon Kinesis Firehose was released on January 10, 2018 and has the same compatibility specifications as Version 1.2.0.

New features

Version 1.1.1 of the Splunk Add-on fixes a bug with CloudTrail field extractions.

Fixed issues

Version 1.1.1 of the Splunk Add-on for Amazon Kinesis Firehose does not have any fixed issues.


Date resolved Issue number Description
2018-01-10 ADDON-16540 Fails to perform cloudtrail field extractions and transformations

Known issues

Version 1.1.1 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.


Date filed Issue number Description
2018-03-22 ADDON-17576 Timestamp for VPC flow logs are based on record's arrival timestamp and are inaccurate
2018-02-28 ADDON-17577 Using the "generate sample findings" option in GuardDuty causes CloudWatch events to not be linebroken.

Third-party software attributions

Version 1.1.1 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.

Version 1.1.0

Version 1.1.0 of the Splunk Add-on for Amazon Kinesis Firehose was released on December 21, 2017 and has the same compatibility specifications as Version 1.1.1.

Fixed issues

Version 1.1.0 of the Splunk Add-on for Amazon Kinesis Firehose does not have any fixed issues.

Known issues

Version 1.1.0 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.

Third-party software attributions

Version 1.1.0 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.

Version 1.0.1

Version 1.0.1 of the Splunk Add-on for Amazon Kinesis Firehose was released on December 7, 2017 and has the same compatibility specifications as Version 1.1.0.

Fixed issues

Version 1.0.1 of the Splunk Add-on for Amazon Kinesis Firehose contains the following fixed issues.


Date resolved Issue number Description
2017-12-07 ADDON-16233 AWS App is not compatible with CloudTrail Logs ingested from Kinesis Firehose

Known issues

Version 1.0.1 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.


Third-party software attributions

Version 1.0.1 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.

Version 1.0.0

Version 1.0.0 of the Splunk Add-on for Amazon Kinesis Firehose was released on November 20, 2017. It was the first release of this add-on.

Known issues

Version 1.0.0 of the Splunk Add-on for Amazon Kinesis Firehose contains the following known issues.

If no issues appear below, no issues have yet been reported.


Date filed Issue number Description
2017-11-20 ADDON-16233 AWS App is not compatible with CloudTrail Logs ingested from Kinesis Firehose

Workaround:
Use AWS Add-On to ingest CloudTrail Logs using the aws:cloudtrail sourcetype. 

Third-party software attributions

Version 1.0.0 of the Splunk Add-on for Amazon Kinesis Firehose does not incorporate any third-party software or libraries.

Last modified on 08 October, 2021
Release notes for the Splunk Add-on for Amazon Kinesis Firehose   Hardware and software requirements for the Splunk Add-on for Amazon Kinesis Firehose

This documentation applies to the following versions of Splunk® Supported Add-ons: released, released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters