splunk-aws-ta-setup

Render offline Splunk_TA_aws assets including inputs.conf, account-setup.md, and validation content.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-aws-ta-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-aws-ta-setup
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-aws-ta-setup
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-aws-ta-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill provides a manual onboarding path for the Splunk Add-on for AWS (Splunk_TA_aws) by generating configuration artifacts such as inputs.conf stanzas, an account-setup runbook, and a CIM plan, enabling operators to onboard AWS data without CloudFormation automation.

Core Features & Use Cases

  • Render offline assets including inputs.conf, account-setup.md, and a placement/CIM plan for the Splunk_TA_aws add-on.
  • Create and configure the event index and account references to support CloudTrail, Config, and GuardDuty ingestion via the manual TA workflow.
  • Validate ingestion readiness with guidance, runbooks, and example validation content to ensure data flows into the aws index.

Quick Start

Render the AWS add-on assets to generate inputs.conf, account-setup.md, and validation artifacts.

Frequently Asked Questions about splunk-aws-ta-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manually onboard Splunk AWS Add-on without CloudFormation?

Manual onboarding for the Splunk AWS Add-on is achieved by rendering offline assets such as inputs.conf stanzas, an account-setup runbook, and validation content, enabling operators to configure AWS data ingestion without CloudFormation automation.

What AWS data sources can I configure with manual Splunk_TA_aws inputs.conf?

Manual inputs.conf configuration supports onboarding CloudTrail, Config, and GuardDuty ingestion paths by generating the required stanzas and account references to route AWS data into the event index.

Does the Splunk AWS Add-on manual setup require network access?

No, the Splunk AWS Add-on manual setup does not require network access. This Skill renders offline assets including inputs.conf, account-setup.md, and validation content without performing any network actions.

How do I validate AWS data ingestion in Splunk after manual TA setup?

You validate AWS data ingestion by using the rendered validation searches and guidance content generated during manual TA setup, which confirm data flows correctly into the aws index for CloudTrail, Config, and GuardDuty inputs.

What is a CIM plan and do I need one for Splunk_TA_aws onboarding?

A CIM plan maps ingested AWS data to Splunk Common Information Model standards. You need one for Splunk_TA_aws onboarding to ensure proper data normalization, and this Skill renders a placement and CIM plan alongside the configuration artifacts.