Create an Amazon CloudWatch Unified Data Store connection in the Data Management app to authenticate federated searches over datasets in Amazon S3 tables.
Create an Amazon CloudWatch Unified Data connection in the Data Management app to authenticate federated searches over CloudWatch Unified Data Store datasets in Amazon S3 tables from your Splunk platform deployment.
- On your Splunk Cloud Platform deployment, in Splunk Web, open the Data Management app.
- Select to enter the Create connection workflow.
- On Select data store, select CloudWatch Unified Data Store. Then select Next.
- On General, provide values for the following settings, and then select Next.
- Select Next to go to the Storage authentication step.
Set up IAM role authentication in your AWS account:
- At the Storage authentication step, select Copy to copy the custom trust policy to your clipboard.
- In a new browser tab, log in to your AWS account, navigate to the Identity and Access Management (IAM) console, and create a role that meets the following requirements:
For more information, see the following topics in the AWS Identity and Access Management User Guide:
- Copy the Amazon Resource Name (ARN) of the role that you configured in step 2.
- Return to the browser tab that shows the Storage authentication page in the Data Management app and then do the following things:
- Paste the ARN into the IAM role ARN field.
- Select I confirm that I have added the tag to the new IAM role.
- Select Next.
- On the Review page, review the connection settings to determine whether the connection is defined correctly. If it is defined correctly, select Create to create the connection.
You now have a CloudWatch Unified Data Store connection that uses an IAM role to authenticate to Amazon S3.
Next, create a dataset that uses this connection to facilitate federated searches over your Amazon CloudWatch Unified Data Store. See Define a CloudWatch Unified Data Store dataset.