We use clustered search heads and clustered forwarders. All the documents on how to set up the AWS account seem to be GUI based. So, we set everything up on one search head. Then copied our Splunk_TA_aws directory to the deployment server and deployed it to all of our forwarders. As that is what the directions for the app say to do. Now we get the following messages:
10-16-2015 22:25:54.800 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_config.py" ERRORNo AWS Account is configured.
I have checked and we have a passwords.conf with the correct info. This all worked fine when it was on the search heads, but putting things on our heavy forwarders just doesn't seem to work. Anyone know where I can add the AWS account info in the Splunk_TA_aws directory?
↧