We have updated our Terms of Service, Code of Conduct, and Addendum.

AWS SQS input not receiving/sending all region messages to Splunk

Ambrosia Iwugo
Ambrosia Iwugo Posts: 1

I recently set up our SQS amazon queue in cribl. Events are forwarding to splunk, however when compared to the pre existing aws logs in Splunk from the Heavyforwarder TA, I noticed we are only pulling in events from only one region via cribl oppose to the 20 actually sending events and being received through the Splunk TA. Any advice on how to troubleshoot an solve this issue?

Tagged:

Answers

  • nthusiast
    nthusiast Posts: 6

    So to understand better, you have 20 queues or 20 regions with queues that your trying to send data?