Search for AWS
Query your AWS estate live, from the Splunk search bar.
Run SPL against the live AWS APIs without leaving Splunk - list resources of any kind over Cloud Control, tail CloudWatch logs and chart CloudWatch metrics, look up CloudTrail events, run Athena queries, and pull Cost Explorer data across every account and region you register. No ingestion, no index storage, and one dashboard per AWS service, grouped the way the AWS console groups them. Search for AWS is in beta: it is not on Splunkbase yet, and is available on request, together with a license for the beta.
Requirements
Splunk versions, supported platforms, the IAM identity, and the network path the app needs
→Installation
Install on a search head, assign roles, register an account, run your first search
→Splunk Cloud
What is different on Splunk Cloud: everything is set from the Setup page, credential choices, and egress
→Concepts
The live-API model, accounts and regions, fan-out, caching, and what the app is not
→Costs and performance
Which AWS APIs bill per call, how the app keeps those calls deliberate, and the search-head footprint
→Command reference
Full SPL reference for awsget, awslogs, awsmetrics, awscloudtrail, awscost, awsathena, awsglue, awstag, and awsjson
→Use cases
Common searches by goal, and how to alert on live AWS state
→Accounts
Register accounts, choose a credential type, attach the IAM policy, lock regions, and override endpoints
→Configuration
The Settings and Cache tabs, and the aws_search.conf they write
→Access control
Splunk roles and capabilities, the shared and per-user credential models, and CloudTrail attribution
→Dashboards
One dashboard per AWS service, grouped the way the console groups them, built on the live commands
→Licensing
Free tier vs paid, what happens at the limits, and entering a key
→Troubleshooting
Find logs and diagnose the common failures
→Support
How to get help and what to include in a request
→Release history
Version history for the Search for AWS app
→