Create a CloudWatch Unified Data Store connection

Create an Amazon CloudWatch Unified Data Store connection in the Data Management app to authenticate federated searches over datasets in Amazon S3 tables.

Create an Amazon CloudWatch Unified Data connection in the Data Management app to authenticate federated searches over CloudWatch Unified Data Store datasets in Amazon S3 tables from your Splunk platform deployment.
  • You must have a Splunk Cloud Platform (SCP) deployment that is hosted on AWS (Amazon Web Services).

  • Your user account on the SCP deployment must have a role with the edit_connections and edit_datasets capabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual.
  • You must have an Amazon Web Services (AWS) account and an AWS IAM role with permissions that let you attach and modify custom trust policies and resource policies for IAM roles. Contact your AWS administrator for assistance with AWS permissions. See IAM role creation in the AWS Identity and Access Management User Guide.
  1. On your Splunk Cloud Platform deployment, in Splunk Web, open the Data Management app.
  2. Select Connections > Create connection to enter the Create connection workflow.
  3. On Select data store, select CloudWatch Unified Data Store. Then select Next.
  4. On General, provide values for the following settings, and then select Next.
    Setting Description
    Connection name Give this connection a name. The connection name must begin with a lowercase letter and can contain only alphanumeric characters, underscores, and hyphens.
    Description (Optional) Provide a description of the connection.
    AWS account ID Enter the 12-digit AWS account ID for the AWS account that contains the datasets you want to search.
    AWS region Select the AWS region for the AWS account.
  5. Select Next to go to the Storage authentication step.
Set up IAM role authentication in your AWS account:
  1. At the Storage authentication step, select Copy to copy the custom trust policy to your clipboard.
  2. In a new browser tab, log in to your AWS account, navigate to the Identity and Access Management (IAM) console, and create a role that meets the following requirements:
    • The role contains the custom trust policy that you copied during step 1.

    • This role has a resource tag where the Key is splunk-assumable-role and the Value is true.

    For more information, see the following topics in the AWS Identity and Access Management User Guide:

    Note: This role also needs specific resource access policies in order to access your Amazon S3 bucket. You will configure these policies during a later step that's described in Set the access policy and permissions for a CloudWatch Unified Data Store dataset. Make a note of the name of this role so you have it available when you create the dataset that you will associate with this connection.
  3. Copy the Amazon Resource Name (ARN) of the role that you configured in step 2.
  4. Return to the browser tab that shows the Storage authentication page in the Data Management app and then do the following things:
    1. Paste the ARN into the IAM role ARN field.
    2. Select I confirm that I have added the tag to the new IAM role.
  5. Select Next.
  6. On the Review page, review the connection settings to determine whether the connection is defined correctly. If it is defined correctly, select Create to create the connection.
You now have a CloudWatch Unified Data Store connection that uses an IAM role to authenticate to Amazon S3.
Next, create a dataset that uses this connection to facilitate federated searches over your Amazon CloudWatch Unified Data Store. See Define a CloudWatch Unified Data Store dataset.