Set the access policy and permissions for a CloudWatch Unified Data Store dataset

Apply the Splunk-generated resource access policy to the IAM role associated with your connection to authenticate access to your Amazon S3 dataset.

After completing the dataset definition steps described in Define a CloudWatch Unified Dataset, finish creating the dataset by applying its resource access policy and permissions to the IAM role associated with the dataset's connection. This resource access policy is generated by Splunk software.

The resource access policy grants access to the S3 table that contains the data you want to search. In addition, if you apply server-side encryption with AWS Key Management service keys (SSE-KMS) to the S3 Table Bucket that contains the S3 table, the resource access policy also includes required information about that encryption.

  • You must have a Splunk Cloud Platform (SCP) deployment that is hosted on AWS (Amazon Web Services).

  • Your user account on the SCP deployment must have a role with the edit_connections and edit_datasets capabilities. See Define roles on the Splunk platform with capabilities in Securing Splunk Cloud Platform.

  • You must have an Amazon Web Services (AWS) account and an AWS IAM role with permissions that let you attach and modify custom trust policies and permissions policies for IAM roles. Contact your AWS administrator for assistance with AWS permissions. See IAM role creation in the AWS Identity and Access Management User Guide.

  • Review the connection this dataset is associated with. Obtain the name of the IAM role that it uses for IAM role authentication. See Create a CloudWatch Unified Data Store connection.
  • You must have completed the Configure dataset step of the Create dataset workflow for a CloudWatch Unified Data Store dataset. See Define a CloudWatch Unified Data Store dataset.
  1. In the Data Management app, at the Update policies step of the Create dataset workflow, indicate whether the the S3 Table Bucket that contains the S3 table for this CloudWatch Unified Data Store dataset uses server-side encryption with AWS Key Management service keys (SSE-KMS).
    Note: Skip this step if you have not applied SSE-KMS encryption to your bucket or your AWS Glue data catalog.
  2. If you select Yes for the SSE-KMS question, follow these instructions to retrieve the the value for the AWS KMS key ARNs setting.
    Note: If you select No for the SSE-KMS question, go to step 3.
    1. In a new browser tab, log in to your AWS account and navigate to the Amazon S3 console.
    2. In the left-hand navigation pane of the Amazon S3 console, select Table buckets.
    3. Select the name of the table bucket that contains the S3 table for this dataset, such as aws-cloudwatch.
    4. Select the bucket Properties tab.
    5. Inspect the Default encryption section. If the Encryption type is Server-side encryption with AWS Key Management Service keys (SSE-KMS), copy the Encryption key ARN that appears below it.
    6. Back in the browser tab that is displaying the Update policies step for your CloudWatch Unified Data Store dataset, paste the Encryption key ARN value that you copied in the previous step into the AWS KMS key ARNs setting.
  3. Select Generate policies to generate a resource access policy.
  4. Select Copy to copy the resource access policy to your clipboard.
  5. Follow these steps to apply the policy to the IAM role that is associated with the connection for this dataset.
    1. Go back to the browser tab that holds your AWS account and navigate to the Identity and Access Management (IAM) console.
    2. In the left-hand navigation pane of the IAM console, select Roles, and then select the name of the role that is used for IAM role authentication by the connection with which this dataset is associated.
    3. In the Permissions policies section of the role, select Add permissions > Create inline policy.
    4. In the Policy editor, select JSON.
    5. Paste the resource access policy that you copied in step 4 into the Policy editor, overwriting the policy template as you do so.
      Note: Resolve security warnings, errors, general warnings, and suggestions before creating the resource access policy.
    6. Select Next.
    7. On the Review and Create page, give your resource access policy a unique and easily identifiable Policy name, and then select Create policy.
  6. If access to your S3 Table is governed by Lake Formation permissions, you must grant additional SELECT and DESCRIBE Lake Formation permissions to the IAM role that is associated with this dataset's connection. For information about how to do this, see Granting table permissions using the named resource method in the AWS Lake Formation Developer Guide.
  7. Select Next.
  8. On the Review page, review your dataset definition. If the details appear correct, select Create Dataset to create your dataset.
You now have a new CloudWatch Unified Data Store dataset that you use in federated searches.

After you create your CloudWatch Unified Data Store dataset, do these things: