Skip to main content
Question

AWS SQS input not receiving/sending all region messages to Splunk

  • March 11, 2025
  • 1 reply
  • 15 views

I recently set up our SQS amazon queue in cribl. Events are forwarding to splunk, however when compared to the pre existing aws logs in Splunk from the Heavyforwarder TA, I noticed we are only pulling in events from only one region via cribl oppose to the 20 actually sending events and being received through the Splunk TA. Any advice on how to troubleshoot an solve this issue?

1 reply

  • Participating Frequently
  • March 11, 2025

So to understand better, you have 20 queues or 20 regions with queues that your trying to send data?