If you change the default value, you must update nf as well. Event extraction relies on the default value of source type. ![]() Specify a value if you want to override the default of aws:billing. Once the input is created, you cannot change its value.Ī source type for the events. If you leave this field empty, the default value is 90 days before the input is configured. This add-on starts to collect data later than this time. Prefixes used to allow AWS to deliver the reports into a specified folder.Ī regular expression used to filter reports by name. In nf, enter 0 or 1 to respectively disable or enable use of private endpoints. The S3 bucket that is configured to hold Billing Reports.Ĭheck the checkbox to use private endpoints of AWS Security Token Service (STS) and AWS Simple Cloud Storage (S3) services for authentication and data collection. ![]() Private Endpoint (Interface VPC Endpoint) of your STS service, which can be configured from your AWS console. Private Endpoint (Interface VPC Endpoint) of your S3 service, which can be configured from your AWS console. See the AWS service endpoints topic in the AWS General Reference manual for more information. Provide an AWS Region only if you want to use specific regional endpoints instead of public endpoints for data collection. The AWS region that contains your bucket. For more information, see Add and manage IAM roles in the Manage accounts for the Splunk Add-on for AWS topic. Verify that your IAMAssume role has enough permission to access your S3 buckets. In nf, enter the friendly name of one of the AWS accounts that you configured on the Configuration page or the name of the automatically discovered EC2 IAM role. In Splunk Web, select an account from the drop-down list. The AWS account or EC2 IAM role the Splunk platform uses to access your Billing data. Fill out the fields as described in the following table:.Click Create New Input > Billing > Billing (Cost and Usage Report).Click Splunk Add-on for AWS in the navigation bar on Splunk Web home.See the following sample inline policy to configure Billing input permissions:įor more information and sample policies, seeĬonfigure a Cost and Usage Report input using Splunk Web ListAllMyBuckets is required when you use an asterisk (*) character. In the Resource section of the policy, specify the Amazon Resource Names (ARNs) of the S3 buckets that contain billing reports for your accounts. You need these required permissions for the S3 bucket to collect your Cost and Usage Reports: ![]() See the Cost and Usage Report section of the AWS documentation for more information on AWS-side configuration steps.Ĭonfigure AWS permissions for the Cost and Usage Report input Timestamps and report names can be used to filter results if you do not want to ingest all the reports.Īfter you configure your Cost and Usage Report inputs, see Access billing data for the Splunk Add-on for AWS for more information about data collection behavior and how to access the preconfigured reports included in the add-on.
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |